Dashboards & Visualizations

Can a Lookup table populate in a dashboard panel?

Anthonylucian
Path Finder

Hey all,

I want to take the content of a lookup and populate it in a dashboard panel in a simple table view.

I tried the simple |inputlookup command which works in the search head but not within the panels.

Is there an easy way to get this done?

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Permissions was my first thought. What happens with the dashboard? Do you get any errors? Can you open the search from the dashboard? Does it give the same results as the dashboard?

View solution in original post

0 Karma

TheFlash
Path Finder

Try creating the fields you need to use by adding your lookup to  automatic lookup and then create the panel you want.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This should work unless if you have access to the lookup table. What have you tried?

0 Karma

Anthonylucian
Path Finder

Ive only tried the |input lookup command.

I tried to review other community questions most indicate on adjusting the source code of the dash.

you believe its a permissions issue?

my user has access to run on the search head and see the contents, but the dash does not?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Permissions was my first thought. What happens with the dashboard? Do you get any errors? Can you open the search from the dashboard? Does it give the same results as the dashboard?

0 Karma

Anthonylucian
Path Finder

I get search does not return any events when it searches in the panel, but If i open up the search from the panel I can see everything.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...