Dashboards & Visualizations

Unable to break column values in a dashboard

luv
Explorer

Hi

I want to show my logs in the dashboard in a tabular form but the problem is my logs are very large hence while displaying the dashboards the _raw events column are going too far from the page, Means if user wants to check _raw events for any events he'd have to scroll the bar for too long to get to the last line of that row. The whole _raw event is showing in a single line,
Is there anyway i can adjust the size of the row or split the lines in the dashboards? So that it'd be easier to read the whole row instead of having to scroll forever to get to the last word of row
suppose i have 3 columns:-
column1 column2 column3
10:30 PM ABC QWERTYUIOPASDFGH JKLZXCVBNMABCDEFG HIJKLMNOPQRSTUVWXYZ
^this 3rd column's value is too large to fit in the page so i have to scroll to the right to get to the last part "HIJKLMNOPQRSTUVWXYZ"

i want it to be like this:-
column1 column2 column3
10:30 PM ABC QWERTYUIOPASDFGH
JKLZXCVBNMABCDEFG
HIJKLMNOPQRSTUVWXYZ

so that i don't have to scroll to the right in order to read the last part "HIJKLMNOPQRSTUVWXYZ"

Tags (3)
0 Karma
1 Solution

lguinn2
Legend

There is a thread about this that should be helpful. Although it is named very differently, it is the same problem:

Table format field size

The accepted answer was a long macro, but if you read the comments, you will find shorter and better solutions.

View solution in original post

lguinn2
Legend

There is a thread about this that should be helpful. Although it is named very differently, it is the same problem:

Table format field size

The accepted answer was a long macro, but if you read the comments, you will find shorter and better solutions.

luv
Explorer

Thanks lguinn that link really helped!! 🙂

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...