Dashboards & Visualizations

Event Action ---> Show Source: To be displayed on dashboard

Ananya_23
Loves-to-Learn Lots

Hi I have a unique request where I want to display the Event Actions -- > Show Source link to be displayed on the dashboard instead of drilling down by opening the query -- > event and then ---> show source.

Capture1.PNG

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ananya_23 ,

you have two choices:

display the raw events (it's usually the first choice in the display options) or use _raw as field in a table visualization.

Ciao.

Giuseppe

0 Karma

Ananya_23
Loves-to-Learn Lots

Hi @gcusello 
_raw
gives me all the details of that particular event agreed.
But here I want to display the "Show Source" link to be displayed on the dashboard

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ananya_23 ,

the only way is adding a JS that makes the same thing, but I cannot help you because I'm not so strong in JS development.

A simpler way is to add an option: display _raw that adds the _raw field to the table command and displays it.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...