Dashboards & Visualizations

customize Dashboard view after upgrade to 5.0.3

gudavasr
Path Finder

Hi,

I have a simple view with about 6 panels. After splunk upgrade to 5.0.3; I click on Edit to move panels but it is not working. I am not familiar with XML code or advanced XML code.
I just need to move panels side-by-side view and leave it.
Can you please help? Thank You

Tags (2)
0 Karma

nfilippi_splunk
Splunk Employee
Splunk Employee

Looks like you are missing the panel element (table, event, chart) for this searchName.

Try this, and it should at least restore the panel editor for you to edit further.

<?xml version='1.0' encoding='utf-8'?>
<dashboard>
    <label>Log Monitoring</label>
    <row>
        <table>
            <searchName>Main Logs</searchName>
            <title>Main Logs</title>
            <drilldown> 
                <link>
                    /app/search/flashtimeline?q=search%20source%3D$row.source$ | sort _time&amp;earliest=$earliest$&amp;latest=$latest$
                </link>
            </drilldown>
        </table>
    </row>
</dashboard>
0 Karma

gudavasr
Path Finder

This is what I have already. Not sure how this is missed when I pasted in above comment.




Main Logs
Main Logs

  /app/search/flashtimeline?q=search%20source%3D$row.source$ | sort _time &amp;earliest=$earliest$&amp;latest=$latest$

  </link>
  </drilldown>
</table>

0 Karma

gudavasr
Path Finder

here is the xml; nothing fancy. I created search query and saved it as dashboard panel. In 4.3.1, I was able to move panels but now, i can't move panels side by side. now all panels are one below the other.
<?xml version='1.0' encoding='utf-8'?>




Main Logs
Main Logs


/app/search/flashtimeline?q=search%20source%3D$row.source$ | sort _time &earliest=$earliest$&latest=$latest$


0 Karma

nfilippi_splunk
Splunk Employee
Splunk Employee

Can you please provide the xml for this view? Also, can you clarify what you mean by "not working"? Do you see the "Add panel" button (enabled/disabled)?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...