I am trying to build a panel where I would like to input the source and present in a radial guaze.
The simple query looks something like this:
index=x host=y source = /logs/zzz* "keyword"| |timechart span=1m count as keyword
And in there I want to be able to change the "zzz" to different options as per input.
Any advice?
Why not keep them all and use the Trellis
feature?
https://docs.splunk.com/Documentation/Splunk/latest/Viz/VisualizationTrellis
Hi @pranay04
To do this you need to edit the dashboard and "add an input". Edit thatinput to set a token called for example "source".
Then in your panel, update the search to look like this:
index=x host=y source = $source$* "keyword |timechart span=1m count as keyword
Here is some more info: https://docs.splunk.com/Documentation/Splunk/7.2.3/Viz/tokens#Using_tokens_in_a_search
Good luck
Great ! Thanks! got it