Dashboards & Visualizations

Dashboard Template

Zyon
Engager

Hello!

I've created a Dashboard with many panels. These panels are create for FebLog.log.

What i need to do now is to add in MarLog.log, and use the same Dashboard and panels to display the same visualization. Is there anyway for me to do so without having to edit the sources one by one in each panel?

Thank You!!

Tags (2)
0 Karma
1 Solution

Dimitri_McKay
Splunk Employee
Splunk Employee

You could pull in FebLog.log as a source as long as two things are taking place.
1. You use the same sourcetype that you used for FebLog.log
2. Your searches are based on that same sourcetype not by index or source.

If you've tied your searches to a specific index or source, then you'll be stuck and have to edit those searches.

View solution in original post

0 Karma

Dimitri_McKay
Splunk Employee
Splunk Employee

You could pull in FebLog.log as a source as long as two things are taking place.
1. You use the same sourcetype that you used for FebLog.log
2. Your searches are based on that same sourcetype not by index or source.

If you've tied your searches to a specific index or source, then you'll be stuck and have to edit those searches.

0 Karma

Ayn
Legend

Not a real answer per se, but the Dashboard Examples app has excellent examples on how to do all kinds of stuff like this. Check it out: http://splunk-base.splunk.com/apps/64805/splunk-dashboard-examples

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...