Dashboards & Visualizations

How to show more selected fields on dashboard event panel

Lgo
Explorer

Hi There,

I have a dashboard I've created to explore XML trace transactions, it works fine, but when trying to find specific parts of the transaction I have to open each event and check if its the correct part, to make it easier I want to be able to include extra selected fields to show the description of the xml event.

I have extracted this field, but cant get it to show on the dashboard, it shows correctly when viewing it in search.

Query is sourcetype=[sourcetype] Description=* ActivityID=[activityid]

It currently shows like this on the dashboard

alt text

But I want it to show like this:
alt text

0 Karma
1 Solution

spayneort
Contributor

add this to your dashboard:

<fields>Description, host, source, sourcetype</fields>

See here for example:

http://docs.splunk.com/Documentation/Splunk/7.0.0/Viz/PanelreferenceforSimplifiedXML#event

View solution in original post

spayneort
Contributor

add this to your dashboard:

<fields>Description, host, source, sourcetype</fields>

See here for example:

http://docs.splunk.com/Documentation/Splunk/7.0.0/Viz/PanelreferenceforSimplifiedXML#event

Lgo
Explorer

Thank you, that worked perfectly!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...