Splunk Search

Is it correct practice to leave an inline search untitled, and only set a title on the "parent" panel?

Graham_Hanningt
Builder

I'm using Splunk (6.3.1) Web to create dashboards. My newbie workflow involves entering a search string in the Search app, playing around on the Visualization tab, and then saving as a dashboard panel.

When I edit the dashboard, the panel and its ("inline") search can each have their own title. But there's only one object in the panel - a chart - and so only the need for a single title.

I've chosen to specify a panel title and leave the searches untitled.

Is what I'm doing reasonable?

I don't see the point of specifying both; and the panel title renders in a larger font, which I prefer.

(I know I'm just scratching the surface of Splunk dashboards; especially, editing them via the Splunk Web UI, not directly editing the XML definition source.)

0 Karma
1 Solution

PPape
Contributor

Hi Graham,

yes this is a valid way. As long as you have only one chart / table / etc. in your Panel.
But you can place more than one Element in your Panel. Therefore i would prefer the Element Title.

View solution in original post

0 Karma

PPape
Contributor

Hi Graham,

yes this is a valid way. As long as you have only one chart / table / etc. in your Panel.
But you can place more than one Element in your Panel. Therefore i would prefer the Element Title.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If this answers your question, please mark it as accepted. If not, please follow up for clarification.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...