Splunk Search

How to Easily Copy/Paste or Extract Multiple Results from a Dash?

interrobang
Explorer



Hi everyone,

Working on a dash for which the goal is to automate manual data entry which needs to take place over 100s of spreadsheets.

Data in question is a stats table showing relations on an xy grid, to be copy pasted into a spreadsheet. Some grids are tiny, eg. 4x4 but some are truly ridiculous.

The dash is taken care of with db data ingested daly and outputing results to a filterable stats table. People can filter by their specific spreadsheet output needs and copy paste straight into excel. This is mostly working and saving tonnes of manual info gathering but unfortunately, for the unlucky people with the ridiculous grids eg. 100x1000. copy/pasting off the dash with multiple pages becomes another problem.

Question being, what efficient ways can i get multiple people the most usable access to their specific filtered extracts from one dash table? eg. making it fully self-service for all.

Ideally it'd be great if automatically a report or something just did everything and mailed everyone, but that creates a new nightmare, with 100s of unique extracts & 100s of people to receive them...

I figure i need some way everyone can visit the dash, dropdown select their id which filters their specific table grid, and they get an option to either automatically copy the whole table (click a button its copied), or download a csv extract or something.

Is anything like this possible from a dash? Any ideas?
Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Depending on how your dashboard is constructed, your users may be able to download a csv of the results from a table. If it is unavailable / greyed out, it could be because it is saved search or derived from a base search. In this instance, they may be able to open the search in a new window and download the results from there, however, I suspect you may not want to expose you users to this capability.

0 Karma

interrobang
Explorer

it's a base search with stats count & xyseries table of data from sql. with a dropdown to filter by the user-id column, which will filter the results specific to the individual user's copy/extract needs.

no options for anything atm, only 'export to pdf' which is no use.  same when opening the panel search directly... could this be disabled? or need a plugin or something? my searching isnt turning up much useful in the way of csv extracts

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

For the panel, do you have an export option?

ITWhisperer_0-1689834733020.png

 

0 Karma

interrobang
Explorer

Nope. Do have a power-user account, guessing that means those export options may need higher access, or currently admin disabled or something?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

A standard user would have access to the export capability, unless your administrator has removed the capability. Please consult with your administrator.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...