Splunk Search

Insert a heading for 4 rows and give name using HTML

vijaykumartcs
Explorer

I have a dashboard which has 11 rows and each row has 4 panels, now out of 11 rows 5rows belong to one application and another 6 rows belong to another application.

I want to combine 5 rows and name it as "Application A" and combine 6 rows and name it as "Application B" within the same dashboard.

Labels (1)
Tags (3)
0 Karma
1 Solution

renjith_nair
Legend

Are you looking for something similar to below?

<dashboard>
  <label>Headings</label>
  <row>
    <panel>
      <html>
      <h1 align="center">Application A</h1>
    </html>
    </panel>
  </row>
  <row>
    <panel>
      <title>First Row</title>
      <table>
        <search>
          <query>|makeresults count=5|eval value=random()</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </table>
    </panel>
    <panel>
      <chart>
        <search>
          <query>| makeresults |eval count=10</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="charting.chart">pie</option>
        <option name="charting.drilldown">none</option>
      </chart>
    </panel>
  </row>
  <row>
    <panel>
      <html>
      <h4 align="center">other rows</h4>
      <h4 align="center">.</h4>
      <h4 align="center">.</h4>
      <h4 align="center">.</h4>
    </html>
    </panel>
  </row>
  <row>
    <panel>
      <html>
      <h1 align="center">Application B</h1>
    </html>
    </panel>
  </row>
  <row>
    <panel>
      <title>6th Row</title>
      <table>
        <search>
          <query>|makeresults count=5|eval value=random()</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
      </table>
    </panel>
  </row>
</dashboard>

 

Happy Splunking!

View solution in original post

renjith_nair
Legend

Are you looking for something similar to below?

<dashboard>
  <label>Headings</label>
  <row>
    <panel>
      <html>
      <h1 align="center">Application A</h1>
    </html>
    </panel>
  </row>
  <row>
    <panel>
      <title>First Row</title>
      <table>
        <search>
          <query>|makeresults count=5|eval value=random()</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </table>
    </panel>
    <panel>
      <chart>
        <search>
          <query>| makeresults |eval count=10</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="charting.chart">pie</option>
        <option name="charting.drilldown">none</option>
      </chart>
    </panel>
  </row>
  <row>
    <panel>
      <html>
      <h4 align="center">other rows</h4>
      <h4 align="center">.</h4>
      <h4 align="center">.</h4>
      <h4 align="center">.</h4>
    </html>
    </panel>
  </row>
  <row>
    <panel>
      <html>
      <h1 align="center">Application B</h1>
    </html>
    </panel>
  </row>
  <row>
    <panel>
      <title>6th Row</title>
      <table>
        <search>
          <query>|makeresults count=5|eval value=random()</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
      </table>
    </panel>
  </row>
</dashboard>

 

Happy Splunking!
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...