Dashboards & Visualizations

Why is dashboard studio column formatting array?

Skins
Path Finder

I'm looking to add some column formatting to some table in dashboard studio - but the option is greyed out saying the column is an array, why is this ? and can i re-factor my search to make it work?

index=test AND host="test" sourcetype=test
| stats latest(state) latest(status) by host name state status
| stats list(name) as NAME list(state) as STATE list(status) as STATUS by hos
Labels (1)
0 Karma

Skins
Path Finder

Thanks!, but the last stats command presents the data in list format as i want.
if i remove that it doesnt give the desired output?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could use mvjoin to convert the multivalue fields into single fields - does that help?

0 Karma

Skins
Path Finder

nope that removes the list formatting - desired output looks like this:

 

host NAME STATE STATUS

host
Disk 0
Disk 1
Disk 2
Disk 3
Disk 4
Online
Online
Online
Online
Online
 Up
 Up
 Up
 Up
 Up
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The stats command is creating three multivalue fileds (arrays) - these appear to be superfluous as the previous stats command has already created a set of events with exactly the same information in. Try removing the last stats command.

0 Karma
Get Updates on the Splunk Community!

Enhance Your Splunk App Development: New Tools & Support

UCC FrameworkAdd-on Builder has been around for quite some time. It helps build Splunk apps faster, but it ...

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...