Dashboards & Visualizations

How to add new values to dropdown in splunk dashboard in default app

Mukunda7
Explorer

Hi ,

I need small help in adding new servers to dropdown list in app dashboard.

 We have some default apps in splunk search head. In one of the app there is a dashboard to monitor login rates of different stadiums for time range in UTC. Those stadiums are under one index X and now they have added two more stadiums under index Y.  Now we need to add those stadiums to that dashboard dropdown to view logins . How can we include these new stadiums to that dashboard. 

I'm admin here this is new task as we don't have splunk developer in the team so can anyone help me from the scratch ?

Thanks in advance..!:)

 

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share the source SimpleXML of the dropdown in the dashboard you want to change so we can see what it is you are dealing with. You don't need to share the whole dashboard code, just the input section defining the dropdown. Pleas share in a code block like so

    <input type="dropdown" token="stadium">
      <label>...
...
    </input>
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Mukunda7,

it's difficoult to help you in a blind situation, anyway, probably the search in the dropdown is

| metasearch index=index_x
| dedup host
| sort host
| table host

If this is your situation, you have only to add the second index to the main search

| metasearch index=index_x OR index=index_y
| dedup host
| sort host
| table host

Ciao.

Giuseppe

0 Karma

Mukunda7
Explorer

@gcusello 

Understood but can we add the another index to the query directly in search head or should I need to push in some other way?

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Mukunda7,

you have to modify the dashboard in this way:

  • open the dashboard,
  • click Edit,
  • click on "Edit Input" of the dropdown,
  • modify the search string adding the second index as in my example,
  • click on Apply of the dropdown,
  • save the Dashboard.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...