I'm building dashboards in a Splunk app, using Splunk Enterprise 9.2.0. I want to be able to run a query on a dashboard, based on my filters, time picker, etc. (with a Submit). This, I know how to do. But, I need to be able to scroll down and do the exact same thing again below, so I can keep my original output up at the top.
I need to know how to basically do this sort of dashboard (all in the same dashboard)
Fieldset 1
** Run the first one, keep that output, and then run the one below, while the other results remain the same
Fieldset 2 (or duplicate)
...and if it's any different, how to keep drilling down to:
Fieldset 3, Fieldset 4, and so on...
Does anyone know how to do that, or is there a book/reference on that? Thanks.
Hi
maybe you could use several row and panels with some reports and/or base and post searches?
See more https://docs.splunk.com/Documentation/Splunk/9.2.0/Viz/Savedsearches
r. Ismo