Splunk Search

Is it correct practice to leave an inline search untitled, and only set a title on the "parent" panel?

Graham_Hanningt
Builder

I'm using Splunk (6.3.1) Web to create dashboards. My newbie workflow involves entering a search string in the Search app, playing around on the Visualization tab, and then saving as a dashboard panel.

When I edit the dashboard, the panel and its ("inline") search can each have their own title. But there's only one object in the panel - a chart - and so only the need for a single title.

I've chosen to specify a panel title and leave the searches untitled.

Is what I'm doing reasonable?

I don't see the point of specifying both; and the panel title renders in a larger font, which I prefer.

(I know I'm just scratching the surface of Splunk dashboards; especially, editing them via the Splunk Web UI, not directly editing the XML definition source.)

0 Karma
1 Solution

PPape
Contributor

Hi Graham,

yes this is a valid way. As long as you have only one chart / table / etc. in your Panel.
But you can place more than one Element in your Panel. Therefore i would prefer the Element Title.

View solution in original post

0 Karma

PPape
Contributor

Hi Graham,

yes this is a valid way. As long as you have only one chart / table / etc. in your Panel.
But you can place more than one Element in your Panel. Therefore i would prefer the Element Title.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If this answers your question, please mark it as accepted. If not, please follow up for clarification.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...