Dashboards & Visualizations

find last time dashboard run

sarit_s
Communicator

Hello

is it possible to get a list of all the dashboards that was running for the last * days ?

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Yes it's possible. You can start with this query, if you have access to _audit log.

 

index=_audit user!=splunk-system-user app=* provenance="*" 
| stats last(_time) as _time count values(provenance) as Dashboard by app

 

r. Ismo 

0 Karma

sarit_s
Communicator

thanks, it looks good but i need the last time of each dashboard and not grouped by app

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Like this?

index=_audit user!=splunk-system-user app=* provenance="*" 
| stats last(_time) as _time count by provenance
| rename provenance as Dashboard

r. Ismo 

0 Karma

sarit_s
Communicator

thanks

is it possible to add the user to this list ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
index=_audit user!=splunk-system-user app=* provenance="*" 
| stats last(_time) as _time values(user) as users count by provenance
| rename provenance as Dashboard

 

If you haven't enough user experience about Splunk and SPL there are lot of trainings available. Some free and other payable. You can found Splunk's own training offerings from https://education.splunk.com/catalog

There is also lot of other training / learning material on other sites including YouTube.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...