I have a dashboard for my application. And in that dashboard, I have an empty panel created, to add the logs of that application when a certain exception occurs. So for that I have added a log.info object with some unique text in it. How do I configure the empty panel on the dashboard so that those specific logs containing unique text should be displayed in the panel for now on.
Assuming your dropdown token name is "environment", try this
env=$environment$ `app_logs(application_name)` "my unique text"
In your panel, define a table with a search query that finds the events with your specific text in.
Hello @ITWhisperer I'm completely new to splunk, could you please be more specific about the query that I need to use?
Start with the search app - what search do you use to find the events you are interested in - for example
index=<your index> "string you want to find"
@ITWhisperer I have a list of environments in a drop-down, so whenever I select a different environment, I should get the logs of that environment in that panel. How do I configure that
Right now my configuration is as follows:
env=dev `app_logs(application_name)` "my unique text"
Assuming your dropdown token name is "environment", try this
env=$environment$ `app_logs(application_name)` "my unique text"