Dashboards & Visualizations

Why is dashboard studio column formatting array?

Skins
Path Finder

I'm looking to add some column formatting to some table in dashboard studio - but the option is greyed out saying the column is an array, why is this ? and can i re-factor my search to make it work?

index=test AND host="test" sourcetype=test
| stats latest(state) latest(status) by host name state status
| stats list(name) as NAME list(state) as STATE list(status) as STATUS by hos
Labels (1)
0 Karma

Skins
Path Finder

Thanks!, but the last stats command presents the data in list format as i want.
if i remove that it doesnt give the desired output?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could use mvjoin to convert the multivalue fields into single fields - does that help?

0 Karma

Skins
Path Finder

nope that removes the list formatting - desired output looks like this:

 

host NAME STATE STATUS

host
Disk 0
Disk 1
Disk 2
Disk 3
Disk 4
Online
Online
Online
Online
Online
 Up
 Up
 Up
 Up
 Up
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The stats command is creating three multivalue fileds (arrays) - these appear to be superfluous as the previous stats command has already created a set of events with exactly the same information in. Try removing the last stats command.

0 Karma
Get Updates on the Splunk Community!

Index This | How many sides does a circle have?

  March 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

New This Month - Splunk Observability updates and improvements for faster ...

What’s New? This month, we’re delivering several enhancements across Splunk Observability Cloud for faster and ...

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...