Splunk Enterprise Security

Is it possible to manually add values to a dashboard panel?

nate_c
New Member

I am trying to count the number of events that I am unable to send to Splunk. I need these in a dashboard where I can just type them in when I get them.

For example, I have 13 events from yesterday and on my dashboard I want to just be able to add them to the current count. This way someone can still see the number of events even though I don't send them to Splunk. The only value I need is a number nothing else.

Is this possible to do, or am I completely crazy? Thank you!

0 Karma

PowerPacked
Builder

Hi @nate_c

you can add, update, delete data by working with a kvstore or lookup.

and you can use lookup commands like inputlookup, outputlookup, lookup to work with kvstore or lookup files & also show these data as panels in the dashboards.

go through this splunk doc, can be helpfull

http://dev.splunk.com/view/webframework-tutorials/SP-CAAAEZT

Thanks

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...