Splunk Search

Custom expand table row visulization

tomasmoser
Contributor

Hi Team,

I have a simple table that I want to show in a dashboard - user search history. Columns "_time" and "search". On top of that I want to see ONLY first line from every row with a search where this search span multiple lines - expandable row with little "arrow" on the left side.

This is probably done via some JavaScript file and custom vizualisation logic. I have seen many examples but none such simple - usually expanded row provide some additional search. I do not want that. Can someone give me a .js code example to achieve my goal?

I want the same output as here in "Search and Reporting" app under "Search History".

Tomas

0 Karma

woodcock
Esteemed Legend
Get Updates on the Splunk Community!

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...