Dashboards & Visualizations

Dashboard Studio: Event Panel in the Table Visualization Format

lcguilfoil
Path Finder

Hello! I am using Dashboard Studio. I created an Events visualization that is currently in the List view. I want to make it into the Table view. This is the source code for the Dashboard Studio dashboard:

 

{
	containerOptions: {},
	"context": {},
	"dataSources": {
		"primary": ds             # the query is index=* | table field1, field2, field3
	},
	"options": {},
	"showLastUpdated": false,
	"showProgressBar": true,
	"type": "splunk.events"
}

 

 

I created something similar to what I'm looking for in Dashboard Classic and this is the code:

 

<panel>
	<event>
		<search>
			<query>index=*</query>
			<earliest>$global_time.earliest$</earliest>
			<latest>$global_time.latest$</latest>
		</search>
		<fields>field, field2, field3</fields>
		<option name="type">table</option>
	</event>
</panel>

 

Labels (3)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @lcguilfoil 

Change your "splunk.events" to "splunk.table" 

So its like this example:

"viz_URfuD3f4": {
            "containerOptions": {},
            "context": {},
            "dataSources": {
                "primary": "ds_0zCzRLMd"
            },
            "options": {},
            "showLastUpdated": false,
            "showProgressBar": false,
            "type": "splunk.table"
        }

 

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

lcguilfoil
Path Finder

Hi @livehybrid,

I appreciate your comment! That's not exactly what I'm looking for. I don't want to use the Table panel, but instead I want to change the Event panel's display to table. I apologize if what I'm saying is unclear. The best example I can give is the same thing I'm aiming for in the Classic Dashboard:

<panel>
	<event>
		<search>
			<query>index=*</query>
			<earliest>$global_time.earliest$</earliest>
			<latest>$global_time.latest$</latest>
		</search>
		<fields>field, field2, field3</fields>
		<option name="type">table</option>
	</event>
</panel>

 

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...