Splunk Search

Table Command: Customization?

nowakdaw
Path Finder

Hello All,

I am wondering if anyone knows if Splunk, or a splunk app can accomplish customizing your table.

For example a search like this: * | table host, source, sourcetype

I would like to be able to interactively move the columns via mouse drag(I know you can specify the order with the table command by what field is typed in first, but interactively as an alternative)

In addition, I would like to be able to collapse my columns/rows and bring them back up interactively.

Does anyone know if this is a possibility either via "out-of-the-box" Splunk or via an app?

Thank you!

Tags (2)
0 Karma
1 Solution

bmacias84
Champion

This currently not available in Splunk or in any app, that I know of. The feature(s) similar to what you discribe will be available in Bubbles the next major 5.x release. Keep in mind that Ace (5.0) release has not been released.

View solution in original post

0 Karma

nowakdaw
Path Finder

Hello bmacias, Thank you for your response. I assume Bubbles and Ace refer to the code names for the releases. Could you point me of where you found this information? I seem to be unable to find it on the webpage. Thank you again for your time.

0 Karma

bmacias84
Champion

This currently not available in Splunk or in any app, that I know of. The feature(s) similar to what you discribe will be available in Bubbles the next major 5.x release. Keep in mind that Ace (5.0) release has not been released.

0 Karma

nowakdaw
Path Finder

@bmacias84, Thank you I appreciate all your help.

0 Karma

bmacias84
Champion

@nowakdaw, I haven't seen any public information regarding this since 5.0 (ACE) has not been released yet. Bubbles will be a 5.x release and has nt release date. The only reason I am event aware of this is because I attended Splunk .conf 2012 and I've been in contact with the Seattle Branch. My co-work was able to particpate in a user experiance show this feature. Sorry I could be of more help.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...