Dashboards & Visualizations

How to show single value decorations with reports embedded inside a dashboard?

changux
Builder

Hi.

I want to show single value decorations with a dashboard that is built with saved searches (reports). I checked the examples of the Dashboard examples app, that suggest:

<searchString>| stats count as value | eval value = 550 | rangemap field=value none=0-99 low=100-199 guarded=200-299 elevated=300-399 high=400-499 severe=500-599 default=none</searchString>

My code is:

<search ref="RPT_search_data_example"></search>

I don't have the searchstring, I have the reference to the saved report.
Also, I modified the base report (RPT_search_data_example) and added the | rangemap ... code but doesn't work. Any suggestion? I knew that change my search tags by searchString is the plan B.

Thanks!

0 Karma
1 Solution

changux
Builder

Finally, the only option was replace the report on the dashboard to a searchstring.

Thanks!

View solution in original post

0 Karma

changux
Builder

Finally, the only option was replace the report on the dashboard to a searchstring.

Thanks!

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Here's a good thread on single value decorations

http://answers.splunk.com/answers/111390/using-single-value-decorations.html

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...