Hello Splunk Gurus,
For a given dashboard, which has tables, I create text fields/drop-down to filter table data. Which of-course takes extra space on UI. I was wondering if Splunk provide the way to create filter on table header like excel without creating separate textbox/drop-down for filter. Any idea?
For example, below table got created by this query
index=micro host=app150*usa.com "API Timeline" |
rex field=_raw "FirstCompTime:(?<FirstComp>[^\,]+)" |
rex field=_raw "SecondCompTime:(?<SecondComp>[^\,]+)" |
rex field=_raw "ThirdCompTime:(?<ThirdComp>[^\,]+)" | table FirstComp, SecondComp, ThirdComp
FirstComp | SecondComp | ThirdComp |
78 | 25 | 31 |
80 | 22 | 34 |
81 | 26 | 36 |
Now i want to create filter on table header; lets say on header name "ThirdComp" like excel as shown below.
Thanks