Dashboards & Visualizations

How to customize "Open in Search" query in dashboard panels bottom right?

amdosh
Explorer

The query that is generated by splunk is quite convoluted and I would like to provide my own query for this "Open In Search" on 1 of the panels in my dashboard. Is it possible to do so?

 

edit: Corrected to "Open in Search"

Labels (1)
Tags (2)
0 Karma

amdosh
Explorer

I was using a baseSearch in this case and realized it's going to be much better to not use it and fire a new search (as the baseSearch had a transaction in it).  I will keep these solutions in mind if similar issues going forward. Thanks for your responses. 

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@amdosh 

You can remove the existing "open in Seach menu" from Panel and add new one with your requirement using JS.

Can you please try below Example?

XML

<dashboard script="myJs.js">
  <label>Sample Dashboard</label>
  <row>
    <panel id="panel1">
      <table>
        <search id="search_1">
          <query>| makeresults count=5 | eval a=1| accum a </query>
        </search>
      </table>
      <html>
        <div id="controlpanel"></div>
      </html>
    </panel>
  </row>
</dashboard>

 

myJs.js

 

require([
    'underscore',
    'jquery',
    "splunkjs/mvc/resultslinkview",
    'splunkjs/mvc',
    'splunkjs/mvc/simplexml/ready!'
], function (_, $, ResultsLinkView, mvc) {


    $(document).ready(function () {

        $('#panel1 .menus').html("")
        
        var resultsLink = new ResultsLinkView({
            id: "resultsLink",
            managerid: "search_1",
            "link.openSearch.search": "index=test with custom SLP",
            "link.openSearch.searchEarliestTime": '0',
            "link.openSearch.searchLatestTime": 'now',
            el: $("#controlpanel")
        });

        resultsLink.render().$el.appendTo($("controlpanel"));


    });
});

 

Refer this document for more options.

https://docs.splunk.com/DocumentationStatic/WebFramework/1.5/compref_resultslinkview.html

 

Thanks
KV


If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.

ITWhisperer
SplunkTrust
SplunkTrust

You can use a drilldown to open a search with a different search string, so rather than using the bottom right, the user clicks on the dashboard panel

Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco &#43; Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...