- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk dash-board - How to show extracted fields on the left like when you search

When I do a normal search I see the extracted fields on the left.
In the dashboard that I am creating, how do I show that info too?
Here is my dashboard - the extracted feilds are not showing on the left;
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi @cyler
You can show values of only one field not all the fields & in your scenario its Hostname Values.
The Box your are showing in the dashboard is Input Tab where you give the Input and Dashboard or Form populates based on the Input you given in that tab.
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

add this to Dashboard XML to get the Hostname values as dropdown
<label>Select a hostname :</label>
<choice value="null">Choose hostname</choice>
<query>Your search | stats count by hostname | sort hostname</query>
</search>
<fieldForLabel>hostname</fieldForLabel>
<fieldForValue>hostname</fieldForValue>
</input>
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Your request is not clear, why would you want the dashboard to show extracted fields on the left?
This is not an expected behaviour in a dashboard.
When you search on the default search app, you get a result of all events matching your search, a dashboard is something different, it is more of a UI to end users to view extracted events (and add more sense to them!) by building charts, tables etc.
I suspect though your use case is something else....can you please elaborate?
