Dashboards & Visualizations

Why is dashboard studio column formatting array?

Skins
Path Finder

I'm looking to add some column formatting to some table in dashboard studio - but the option is greyed out saying the column is an array, why is this ? and can i re-factor my search to make it work?

index=test AND host="test" sourcetype=test
| stats latest(state) latest(status) by host name state status
| stats list(name) as NAME list(state) as STATE list(status) as STATUS by hos
Labels (1)
0 Karma

Skins
Path Finder

Thanks!, but the last stats command presents the data in list format as i want.
if i remove that it doesnt give the desired output?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could use mvjoin to convert the multivalue fields into single fields - does that help?

0 Karma

Skins
Path Finder

nope that removes the list formatting - desired output looks like this:

 

host NAME STATE STATUS

host
Disk 0
Disk 1
Disk 2
Disk 3
Disk 4
Online
Online
Online
Online
Online
 Up
 Up
 Up
 Up
 Up
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The stats command is creating three multivalue fileds (arrays) - these appear to be superfluous as the previous stats command has already created a set of events with exactly the same information in. Try removing the last stats command.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...