Dashboards & Visualizations

Data Table field changes for Dashboards

jasonhblackwell
Explorer

Splunk Dashboard newbie here and so far no search has yielded an answer. Right now I am building a Dashboard for management using the Data table Panel type. Right now the tables are showing the fields: times, host, index, source, sourcetype. I need the data tables to display some of my custom fields. This sounds very easy so I assume I am just missing something. Is this possible?

Tags (1)
0 Karma
1 Solution

Genti
Splunk Employee
Splunk Employee

try adding the

<fields>_time, host, source, sourcetype, field1, field2,etc..</fields>

attribute right under the search that populates the dashboard.
see if this helps

View solution in original post

0 Karma

thall79
Communicator

If you can post the XML you are using. Travis.

0 Karma

Genti
Splunk Employee
Splunk Employee

try adding the

<fields>_time, host, source, sourcetype, field1, field2,etc..</fields>

attribute right under the search that populates the dashboard.
see if this helps

0 Karma

Genti
Splunk Employee
Splunk Employee

Glad that worked! Cheers! 🙂

0 Karma

jasonhblackwell
Explorer

Thank you Genti! I knew it would be something easy. 😛

0 Karma
Get Updates on the Splunk Community!

Index This | A sphere has three, a circle has two, and a point has zero. What is it?

September 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...