I am creating a Dashboard from Splunk log
In this dashboard, I want to want to add the filter to each column. Just by writing into filter text box, data need to be filtered. something like this.
I have also asked same question on stackoverflow.
| multisearch [ |makeresults | eval _time = " Search Time", message = " Search Message" ] [ YOUR ORIGINAL SEARCH HERE ]
If you need it to be tokenized, then like this:
| multisearch [ |makeresults | eval _time = " " . $time_token$, message = " " . $message_token$ ] [ YOUR ORIGINAL SEARCH HERE ]