Dashboards & Visualizations

Dashboard Template

Zyon
Engager

Hello!

I've created a Dashboard with many panels. These panels are create for FebLog.log.

What i need to do now is to add in MarLog.log, and use the same Dashboard and panels to display the same visualization. Is there anyway for me to do so without having to edit the sources one by one in each panel?

Thank You!!

Tags (2)
0 Karma
1 Solution

Dimitri_McKay
Splunk Employee
Splunk Employee

You could pull in FebLog.log as a source as long as two things are taking place.
1. You use the same sourcetype that you used for FebLog.log
2. Your searches are based on that same sourcetype not by index or source.

If you've tied your searches to a specific index or source, then you'll be stuck and have to edit those searches.

View solution in original post

0 Karma

Dimitri_McKay
Splunk Employee
Splunk Employee

You could pull in FebLog.log as a source as long as two things are taking place.
1. You use the same sourcetype that you used for FebLog.log
2. Your searches are based on that same sourcetype not by index or source.

If you've tied your searches to a specific index or source, then you'll be stuck and have to edit those searches.

0 Karma

Ayn
Legend

Not a real answer per se, but the Dashboard Examples app has excellent examples on how to do all kinds of stuff like this. Check it out: http://splunk-base.splunk.com/apps/64805/splunk-dashboard-examples

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...