Dashboards & Visualizations

How to display only certain fields from data source in table for dashboard studio?

rajashekar_s
Path Finder

Hello,

I have been building a dashboard in dashboard studio and was looking for some help wrt implementing the fields option in XML dashboard in dashboard studio

If my panel in XML dashboard has like 5 fields and I want to display only 3 in the table, we can use this

<fields>[field1,field2,field3]</fields>

However when I download the panel results, I will still be able to view all the 5 fields with this

 

I am looking to do something same in dashboard studio and I am not able to get the functionality. I have tried using header option in Table option and didn't get any success.

 

{
"type": "splunk.table",
"options": {
"tableFormat": {
"headerBackgroundColor": "#0E6162",
"rowBackgroundColors": "> table | seriesByIndex(0) | pick(tableAltRowBackgroundColorsByBackgroundColor)",
"rowColors": "> rowBackgroundColors | maxContrast(tableRowColorMaxContrast)",
"headerColor": "> headerBackgroundColor | maxContrast(tableRowColorMaxContrast)"
},
"backgroundColor": "#ffffff",
"table": "> [\"field1\",\"field2\"]", -> didnt work
"headers": "> table | getField([\"field1\",\"field2\"])", -> didnt work
"showInternalFields": false
},
"dataSources": {
"primary": "ds_TlbXBz5i"
},
"context": {},
"showProgressBar": false,
"showLastUpdated": false
}
Labels (2)
0 Karma

lindonmorris
Explorer

Hi, I was going to reply and ask if you ever solved this, but I just did myself.

Name your field _something and untick "show hidden fields". By default the only hidden field that shows is _time, doing this effectively hides your other fields.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...