I have a dashboard with 4 panels/searches. I want to implement the following scenario :-
<\ FORM>
< searchTemplate >FIRST BASE SEARCH< /searchTemplate >
< postProcessSearch > Post Processing search 1 < /postProcessSearch>
< postProcessSearch > Post Processing search 2 < /postProcessSearch>
< searchTemplate >SECOND BASE SEARCH< /searchTemplate >
< postProcessSearch > Post Processing search 3 < /postProcessSearch>
< postProcessSearch > Post Processing search 4 < /postProcessSearch>
<\ /FORM>
Use the id=
and base=
labels. Name your base searches with id
and refer to them with base
.
<form>
<label>Multiple Post Process Search</label>
<description>Each panel post processes the base search through a separate search pipeline. Each Base Search is Named</description>
<search id="First_Base_Search">
<query>index=_internal | head 1000</query>
</search>
<search id="Second_Base_Search">
<query>index=_internal source=*splunkd.log | stats count by component, log_level</query>
</search>
<fieldset autoRun="true" submitButton="false">
<input type="time" searchWhenChanged="true">
<default>
<earliestTime>-24h</earliestTime>
<latestTime>now</latestTime>
</default>
</input>
</fieldset>
<row>
<chart>
<title>Events over Time(First)</title>
<search base="First_Base_Search">
<query>timechart count</query>
</search>
<option name="charting.chart">column</option>
</chart>
<table>
<title>Top Sourcetypes(First)</title>
<search base="First_Base_Search">
<query>top limit=100 sourcetype | eval percent = round(percent,2)</query>
</search>
<option name="displayRowNumbers">true</option>
</table>
</row>
<row>
<chart>
<title>Events Count by Log Level(Second)</title>
<search base="Second_Base_Search">
<query>| stats sum(count) AS count by log_level</query>
</search>
<option name="charting.chart">column</option>
</chart>
<table>
<title>Error Count by Component(Second)</title>
<search base="Second_Base_Search">
<query>| search log_level=error | stats sum(count) AS count by component</query>
</search>
<option name="displayRowNumbers">true</option>
</table>
</row>
</form>