Dashboards & Visualizations

find last time dashboard run

sarit_s
Communicator

Hello

is it possible to get a list of all the dashboards that was running for the last * days ?

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Yes it's possible. You can start with this query, if you have access to _audit log.

 

index=_audit user!=splunk-system-user app=* provenance="*" 
| stats last(_time) as _time count values(provenance) as Dashboard by app

 

r. Ismo 

0 Karma

sarit_s
Communicator

thanks, it looks good but i need the last time of each dashboard and not grouped by app

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Like this?

index=_audit user!=splunk-system-user app=* provenance="*" 
| stats last(_time) as _time count by provenance
| rename provenance as Dashboard

r. Ismo 

0 Karma

sarit_s
Communicator

thanks

is it possible to add the user to this list ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
index=_audit user!=splunk-system-user app=* provenance="*" 
| stats last(_time) as _time values(user) as users count by provenance
| rename provenance as Dashboard

 

If you haven't enough user experience about Splunk and SPL there are lot of trainings available. Some free and other payable. You can found Splunk's own training offerings from https://education.splunk.com/catalog

There is also lot of other training / learning material on other sites including YouTube.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...