Dashboards & Visualizations

Why is dashboard studio column formatting array?

Skins
Path Finder

I'm looking to add some column formatting to some table in dashboard studio - but the option is greyed out saying the column is an array, why is this ? and can i re-factor my search to make it work?

index=test AND host="test" sourcetype=test
| stats latest(state) latest(status) by host name state status
| stats list(name) as NAME list(state) as STATE list(status) as STATUS by hos
Labels (1)
0 Karma

Skins
Path Finder

Thanks!, but the last stats command presents the data in list format as i want.
if i remove that it doesnt give the desired output?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could use mvjoin to convert the multivalue fields into single fields - does that help?

0 Karma

Skins
Path Finder

nope that removes the list formatting - desired output looks like this:

 

host NAME STATE STATUS

host
Disk 0
Disk 1
Disk 2
Disk 3
Disk 4
Online
Online
Online
Online
Online
 Up
 Up
 Up
 Up
 Up
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The stats command is creating three multivalue fileds (arrays) - these appear to be superfluous as the previous stats command has already created a set of events with exactly the same information in. Try removing the last stats command.

0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...