Splunk Search

Convert saved search to inline search

ma_anand1984
Contributor

I have a dashboard with 10 graphs all pointing to one saved search each. what is the easiest way to convert all of them to inline search at One GO?

Tags (4)
0 Karma
1 Solution

MHibbin
Influencer

To check my understanding, you want to convert 10 savedSearches into 10 searches which generate 10 panels on your dashboard?

Did you create your view using XML? - Or did you create it through the tools provided by Splunk (i.e. Search>> Create...>> Dashboard panel)?

If you did it using the tools provided by Splunk, the quickest way I can think would be to navigate to the view, click the "Edit" button, and then for each panel, edit the search, and then click "edit in-line" (or something to that effect).

Other than that the quickest way would be to copy the search strings from the saved searches to a notepad (or something similar) and then edit the XML directly, by replacing your saved searches with searches and adding the search string.

No one-shot method that I've come across, as there are multiple searches being used. You can look at the UI examples app for help on a lot of dashboarding requirements.

Hope this helps,

MHibbin

View solution in original post

0 Karma

pbugeja
New Member

Relatively new user of Splunk and have noticed a possibly bug with the "Clone to Inline Pivot" functionality when editing a Dashboard Panel by clicking on the Search Report icon in order to use a Time Range Picker for Panels in a Dashboard. This will be very handy function to synchronize all panels in a dashboard.

I click on Inline Search icon, choose "Clone to Inline Pivot" and it does not change the icon to Inline Search, hence not prompted to add the Time Range Picker to the panel.

I am using Splunk Enterprise 6.5.1

Thanks, Paul

0 Karma

MHibbin
Influencer

To check my understanding, you want to convert 10 savedSearches into 10 searches which generate 10 panels on your dashboard?

Did you create your view using XML? - Or did you create it through the tools provided by Splunk (i.e. Search>> Create...>> Dashboard panel)?

If you did it using the tools provided by Splunk, the quickest way I can think would be to navigate to the view, click the "Edit" button, and then for each panel, edit the search, and then click "edit in-line" (or something to that effect).

Other than that the quickest way would be to copy the search strings from the saved searches to a notepad (or something similar) and then edit the XML directly, by replacing your saved searches with searches and adding the search string.

No one-shot method that I've come across, as there are multiple searches being used. You can look at the UI examples app for help on a lot of dashboarding requirements.

Hope this helps,

MHibbin

0 Karma

ma_anand1984
Contributor

thank you MHibbin for your time. I'm aware of both the methods you told. I was checking whether there is any magic that does it in one Shot.

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...