Splunk Search

Custom expand table row visulization

tomasmoser
Contributor

Hi Team,

I have a simple table that I want to show in a dashboard - user search history. Columns "_time" and "search". On top of that I want to see ONLY first line from every row with a search where this search span multiple lines - expandable row with little "arrow" on the left side.

This is probably done via some JavaScript file and custom vizualisation logic. I have seen many examples but none such simple - usually expanded row provide some additional search. I do not want that. Can someone give me a .js code example to achieve my goal?

I want the same output as here in "Search and Reporting" app under "Search History".

Tomas

0 Karma

woodcock
Esteemed Legend
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...