Getting Data In

Defined custom Visualization in Dashboard Studio

hieuba
Loves-to-Learn Lots

Hi,


I am creating a Dashboard and using the Dashboard Studio template, and previously I developed a Splunk

Visualization. How can I define a Splunk Visualization on Dashboard Studio? Because by default, I can only

choose from the available Splunk Visualizations that Splunk has provided.

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @hieuba 

i assume you created a custom Visualization in Splunk Classic Dashboards and now you would like to recreate that one thru the Splunk Dashboard Studio... is that correct, pls suggest us. 

maybe could you pls tell us more details about the custom dashboard you are looking to create in the Dashboard Studio pls, thanks. 

0 Karma

hieuba
Loves-to-Learn Lots

Hi @inventsekar ,

you're correct, i have a custom Missle Map Dasboard (only change js code), and i want to defined its as a visualization type in Splunk Dashboard Studio.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @hieuba Could you pls share with us your old dashboard query(SPL) - custom Missle Map Dasboard

so, that we can try to reproduce it on Dashboard Studio, thanks. 

0 Karma

hieuba
Loves-to-Learn Lots

Hi @inventsekar ,

Here is my SPL for Missle Map,

| tstats `security_content_summariesonly` count from datamodel=Intrusion_Detection.IDS_Attacks where (NOT IDS_Attacks.src IN(192.168.0.0/16, 172.16.0.0/12, 10.0.0.0/8, 8.8.8.8, 0.0.0.0, 1.1.1.1, 0:0:0:0:0:0:0:1,"unknown",34.87.171.169 )) NOT IDS_Attacks.severity IN (low, informational) by IDS_Attacks.src | rename IDS_Attacks.* as *
| eval animate="true"
| iplocation dest prefix=end_
| iplocation src prefix=start_
| eval end_lat=if(isnull(end_lat),21.007647, end_lat)
| eval end_lon=if(isnull(end_lon),105.807235, end_lon)
| eval color = case(count <= 100, "#8fce00", count > 100 AND count <= 300, "#ed8821", 1=1, "#f44336")
| eval end_City="Hanoi", end_Country="Vietnam", end_Region="Hanoi"
| sort -count
| dedup start_Country
| table animate color count dest end_City end_Country end_Region end_lat end_lon src start_City start_Country start_Region start_lat start_lon

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...