Dashboards & Visualizations

How to edit my dashboard to show interesting and selected fields?

sravankaripe
Communicator

my dashboard is like this

alt text

it shows events so far
i want the dashboard should also show the
interesting fields
and selected fields

alt text

how can i do this?

0 Karma
1 Solution

DalJeanis
Legend

A proper dashboard has a purpose of producing a very targeted window onto specific data. Duplicating all of splunk's native search screen functionality would require, in essence, all of splunk's native search screen code...

What are you trying to achieve with this particular dashboard? It looks like you are looking for specific kinds of errors, searching by host, within various development through production regions. (In my environment, those would be different hosts as well)

It might be better to start with identifying the most useful or commonly needed fields, and adding those to your dashboard, rather than cluttering it with everything possible. Use a click-through, or a second panel in the dash, to inspect any particular event further.

View solution in original post

DalJeanis
Legend

A proper dashboard has a purpose of producing a very targeted window onto specific data. Duplicating all of splunk's native search screen functionality would require, in essence, all of splunk's native search screen code...

What are you trying to achieve with this particular dashboard? It looks like you are looking for specific kinds of errors, searching by host, within various development through production regions. (In my environment, those would be different hosts as well)

It might be better to start with identifying the most useful or commonly needed fields, and adding those to your dashboard, rather than cluttering it with everything possible. Use a click-through, or a second panel in the dash, to inspect any particular event further.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...