Dashboards & Visualizations

dynamic panel creation

VI371887
Path Finder

Hi all need some help with dashboards..
does splunk supports creation of dashboard panels dynamically.

let's say you have 3 Virtual machines, each with one panel showing cpu, memory, now if a new machine is introduced the splunk should automatically create a similar panel for newly introduced virtual machine or jvm.

Tags (1)
0 Karma
1 Solution

tiagofbmm
Influencer

Yes you can do that using the trellis:

In the following example you will get one panel per each of the sourcetype values existent in the search. So if a new one appears, then you'll get one more panel.

Copy the example and test it yourself. Let me know if it is what you are looking for

<dashboard>
  <label>Trellis</label>
  <row>
    <panel>
      <single>
        <search>
          <query>index=_internal | stats count by sourcetype</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
        <option name="refresh.display">progressbar</option>
        <option name="trellis.enabled">1</option>
        <option name="trellis.size">small</option>
        <option name="trellis.splitBy">sourcetype</option>
      </single>
    </panel>
  </row>
</dashboard>

View solution in original post

0 Karma

tiagofbmm
Influencer

Yes you can do that using the trellis:

In the following example you will get one panel per each of the sourcetype values existent in the search. So if a new one appears, then you'll get one more panel.

Copy the example and test it yourself. Let me know if it is what you are looking for

<dashboard>
  <label>Trellis</label>
  <row>
    <panel>
      <single>
        <search>
          <query>index=_internal | stats count by sourcetype</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
        <option name="refresh.display">progressbar</option>
        <option name="trellis.enabled">1</option>
        <option name="trellis.size">small</option>
        <option name="trellis.splitBy">sourcetype</option>
      </single>
    </panel>
  </row>
</dashboard>
0 Karma

VI371887
Path Finder

My organization has Splunk 6.5.2 and as per trellis about series, it was debuted 6.6 version.
hence I am unable to test this out.

Thanks for the quick response.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...