Getting Data In

How can I add a UI element in a dashboard to select the source?

czervos
Explorer

I have created some dashboard that I use to expedite debugging of certain issues with one of our applications. The issue I am having and I'd like to improve upon is that currently the source files are hardcoded into the searches of the dashboards. I know I can do a global search and replace in the XML to get it to look at other source files but this is not very user friendly if I want to share this dashboard/tool with others. Is there a way to add a UI element to do this much like the time - drop down in dashboards & apps?

I tried to do this manually and managed to create the UI element. However I can't get the source = $newsource to be replaced in the multiple searches that create the views of the dashboard.

TIA

Tags (2)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi czervos,

in addition to @somesoni2 answer, take a look at this nice example from the docs. If you follow this, you should be able to get it working.

cheers, MuS

View solution in original post

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi czervos,

in addition to @somesoni2 answer, take a look at this nice example from the docs. If you follow this, you should be able to get it working.

cheers, MuS

0 Karma

somesoni2
Revered Legend

You can create a dropdown to hold the source data (use |metadata type=sources index=main | table source) and then use the dropdown token in your search.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...