Dashboards & Visualizations

How to edit my dashboard to show interesting and selected fields?

sravankaripe
Communicator

my dashboard is like this

alt text

it shows events so far
i want the dashboard should also show the
interesting fields
and selected fields

alt text

how can i do this?

0 Karma
1 Solution

DalJeanis
Legend

A proper dashboard has a purpose of producing a very targeted window onto specific data. Duplicating all of splunk's native search screen functionality would require, in essence, all of splunk's native search screen code...

What are you trying to achieve with this particular dashboard? It looks like you are looking for specific kinds of errors, searching by host, within various development through production regions. (In my environment, those would be different hosts as well)

It might be better to start with identifying the most useful or commonly needed fields, and adding those to your dashboard, rather than cluttering it with everything possible. Use a click-through, or a second panel in the dash, to inspect any particular event further.

View solution in original post

DalJeanis
Legend

A proper dashboard has a purpose of producing a very targeted window onto specific data. Duplicating all of splunk's native search screen functionality would require, in essence, all of splunk's native search screen code...

What are you trying to achieve with this particular dashboard? It looks like you are looking for specific kinds of errors, searching by host, within various development through production regions. (In my environment, those would be different hosts as well)

It might be better to start with identifying the most useful or commonly needed fields, and adding those to your dashboard, rather than cluttering it with everything possible. Use a click-through, or a second panel in the dash, to inspect any particular event further.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...