Dashboards & Visualizations

How to show more selected fields on dashboard event panel

Lgo
Explorer

Hi There,

I have a dashboard I've created to explore XML trace transactions, it works fine, but when trying to find specific parts of the transaction I have to open each event and check if its the correct part, to make it easier I want to be able to include extra selected fields to show the description of the xml event.

I have extracted this field, but cant get it to show on the dashboard, it shows correctly when viewing it in search.

Query is sourcetype=[sourcetype] Description=* ActivityID=[activityid]

It currently shows like this on the dashboard

alt text

But I want it to show like this:
alt text

0 Karma
1 Solution

spayneort
Contributor

add this to your dashboard:

<fields>Description, host, source, sourcetype</fields>

See here for example:

http://docs.splunk.com/Documentation/Splunk/7.0.0/Viz/PanelreferenceforSimplifiedXML#event

View solution in original post

spayneort
Contributor

add this to your dashboard:

<fields>Description, host, source, sourcetype</fields>

See here for example:

http://docs.splunk.com/Documentation/Splunk/7.0.0/Viz/PanelreferenceforSimplifiedXML#event

Lgo
Explorer

Thank you, that worked perfectly!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...