Splunk Search

How to add a toggle to hide/unhide fields in a table in Splunk Dashboard?

PotatoDataUser
Explorer

I am working on a dashboard that has a bunch of field and will be used by multiple teams and people who will be needing different fields from the table. 
Is there anyway to add a toggle or filter or anything similar to give a couple of presets (ex fields A D E H to preset 1 for team 1, fields B C D F G to preset 2 for team 2 and so on)
I also use filters on fields in the dashboard table as well if possible i would want hiding of the field to not impact the filters at all. 

Thanks in advance.

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could design an input which sets the fields a particular team needs and use that token in a table command alongside the fields which are common to all teams

| table _time comoon1 common2 $teamfields$
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...