Dashboards & Visualizations

One value to rule them all

blurblebot
Communicator

Dear answers Yodas,

I'm trying to find out whether there is a available feature that allows me to go to a dashboard where I can enter a single value at which multiple searches are pointed. I want the results for those searches to populate multiple panels based on those searches. In my quiet, warm, softly-lit universe the XML would look like any other dashboard's, except there would be a variable in place of this value for all of the searches I want.

Does anyone have anything that approaches this functionality?

Thank you!

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

This is exactly how forms (and views in general in Splunk) work. Please see: http://www.splunk.com/base/Documentation/latest/Developer/FormIntro and the rest of the form section. Advanced XML gives you even more flexibility.

View solution in original post

blurblebot
Communicator

I totally knew that, i was just checking to see if you guys...

thanks.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

This is exactly how forms (and views in general in Splunk) work. Please see: http://www.splunk.com/base/Documentation/latest/Developer/FormIntro and the rest of the form section. Advanced XML gives you even more flexibility.

rroberts
Splunk Employee
Splunk Employee

You can find at least two examples in the ui_examples app. It's free and can be downloaded from www.splunkbase.com. There are two views that might meet your needs. 1. form5: Select sourcetype from a selection box. ...<input type="dropdown" token="sourcetype"> <label>Sourcetype</label>... Pass value to search string $sourcetype$ in multi HiddenSearch modules. -OR- 2. Advanced_dashboard4: Using advanced view XML. 1 lister driving multiple elements.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...