Dashboards & Visualizations

Why is dashboard studio column formatting array?

Skins
Path Finder

I'm looking to add some column formatting to some table in dashboard studio - but the option is greyed out saying the column is an array, why is this ? and can i re-factor my search to make it work?

index=test AND host="test" sourcetype=test
| stats latest(state) latest(status) by host name state status
| stats list(name) as NAME list(state) as STATE list(status) as STATUS by hos
Labels (1)
0 Karma

Skins
Path Finder

Thanks!, but the last stats command presents the data in list format as i want.
if i remove that it doesnt give the desired output?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could use mvjoin to convert the multivalue fields into single fields - does that help?

0 Karma

Skins
Path Finder

nope that removes the list formatting - desired output looks like this:

 

host NAME STATE STATUS

host
Disk 0
Disk 1
Disk 2
Disk 3
Disk 4
Online
Online
Online
Online
Online
 Up
 Up
 Up
 Up
 Up
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The stats command is creating three multivalue fileds (arrays) - these appear to be superfluous as the previous stats command has already created a set of events with exactly the same information in. Try removing the last stats command.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...