Dashboards & Visualizations

customize Dashboard view after upgrade to 5.0.3

gudavasr
Path Finder

Hi,

I have a simple view with about 6 panels. After splunk upgrade to 5.0.3; I click on Edit to move panels but it is not working. I am not familiar with XML code or advanced XML code.
I just need to move panels side-by-side view and leave it.
Can you please help? Thank You

Tags (2)
0 Karma

nfilippi_splunk
Splunk Employee
Splunk Employee

Looks like you are missing the panel element (table, event, chart) for this searchName.

Try this, and it should at least restore the panel editor for you to edit further.

<?xml version='1.0' encoding='utf-8'?>
<dashboard>
    <label>Log Monitoring</label>
    <row>
        <table>
            <searchName>Main Logs</searchName>
            <title>Main Logs</title>
            <drilldown> 
                <link>
                    /app/search/flashtimeline?q=search%20source%3D$row.source$ | sort _time&amp;earliest=$earliest$&amp;latest=$latest$
                </link>
            </drilldown>
        </table>
    </row>
</dashboard>
0 Karma

gudavasr
Path Finder

This is what I have already. Not sure how this is missed when I pasted in above comment.




Main Logs
Main Logs

  /app/search/flashtimeline?q=search%20source%3D$row.source$ | sort _time &amp;earliest=$earliest$&amp;latest=$latest$

  </link>
  </drilldown>
</table>

0 Karma

gudavasr
Path Finder

here is the xml; nothing fancy. I created search query and saved it as dashboard panel. In 4.3.1, I was able to move panels but now, i can't move panels side by side. now all panels are one below the other.
<?xml version='1.0' encoding='utf-8'?>




Main Logs
Main Logs


/app/search/flashtimeline?q=search%20source%3D$row.source$ | sort _time &earliest=$earliest$&latest=$latest$


0 Karma

nfilippi_splunk
Splunk Employee
Splunk Employee

Can you please provide the xml for this view? Also, can you clarify what you mean by "not working"? Do you see the "Add panel" button (enabled/disabled)?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...