Splunk Dev

How to create User Input form for existing index data

aravindp
Explorer

I'm getting real time twitter feed to Splunk and created dashboards as per user requirements. Now we need to train our datasets for auto ML(Machine Learning). For that I want to create a dashboard with the fields like "TweetText", "Sentiment", Score and Date fields.
Sentiment may be "Negative" or "Positive" or "Neutral".

I want to create another field for user Input (for example say "True Sentiment", I would like to give dropdown options like "True Positive" OR "True Negative" OR "True Neutral".

Please note, the data is coming to Splunk in real time, how shall we enable edit option for users to add input like this? Please advise with some XML code. Thanks

Tags (1)
0 Karma

adonio
Ultra Champion

hello there,
i cant fully understand the question and / or the challenge you are facing. can you elaborate?
how would you like the user to interact with the data?
in any case, all the samples you need are here:

https://docs.splunk.com/Documentation/Splunk/7.2.3/Viz/Buildandeditforms

iirc there is also a blog on splunknig twiter data that has some twiter dashboard code in it.

hope it helps

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...