All Apps and Add-ons

Tour Creation App for Splunk -- How to work with a default view that has many variables?

gsopkoTC
Path Finder

For our app: the default view isn't:

tc_view_main

It's actually more like this:

tc_view_main?form.start=-30d&form.span=1d&form.indicator_type=&form.rating=&form.confidence=&form.state=New&form.indicator=&form.victim=*&earliest=0&latest=

By default, the Splunk Tour App appends to tc_view_main as such:

tc_view_main?tour=welcome_to_threatconnect_for_splunk

But then our app appends the above remainder for the view of that landing dashboard. I've tried adding the ?tour=welcome_to_threatconnect_for_splunk to the end, used an & instead of a ? but still no dice. I'll try via the conf file but I was hoping to use the App for it as it takes the guesswork out of the DOM elements. My guess is that our app loads the default view and then a page refresh appends and we loose the tour capability.

0 Karma

ebond_splunk
Splunk Employee
Splunk Employee

Also Also, theres a new version of the Splunk Tour Creation App (v3) which may help you...

0 Karma

ebond_splunk
Splunk Employee
Splunk Employee

@gsopkoTC

So sorry for the late reply here! Just now seeing this. So, I think this will only work in splunk 6.6 and above. There was a bug in Splunk 5.x that didn't allow for tours to be run properly on dashboards... only views. is tc_view_main setup as a dashboard?

Also, are you still seeing the issue?

0 Karma

gsopkoTC
Path Finder

I created a VM of Centos7x64 and Splunk 6.5.5 and still not working. Just wondering if anyone had any insight to this as I see the pre-pended tour token but the tour doesn't start.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...