All Posts

Find Answers
Ask questions. Get answers. Find technical product solutions from passionate members of the Splunk community.

All Posts

Dashboard studio gives me the ability to drop panels and and move them around, which I love.  I can drag a panel on top of another and quickly create two equal size panels, each 50% of the size of th... See more...
Dashboard studio gives me the ability to drop panels and and move them around, which I love.  I can drag a panel on top of another and quickly create two equal size panels, each 50% of the size of the dashboard.  If I drag a 3rd panel into the same area though, I get three panels, one of which is 50% of the screen, and the other two are 25% each.  Is it possible to get them to be three equal sizes (~33%) or is my only option to fiddle with the sliders a bit and settle for good enough?
@JLange  you're welcome 
The way we've achieved this in the past is to use a "Tab Rotator" browser extension and then open the intended dashboards in different tabs of the browser, rotating between. You will also need to en... See more...
The way we've achieved this in the past is to use a "Tab Rotator" browser extension and then open the intended dashboards in different tabs of the browser, rotating between. You will also need to ensure that the refresh on your dashboard searches is configured to refresh at the desire interval. For Dashboard Studio dashboard you can set the following within the "options" JSON object for each of your searches: "refresh": "30s"  For XML dashboard set the refresh attribute in your <dashboard> or <form> stanza. See docs for more info I hope this helps! Will
I have few Dashboards in splunk I want to play them on TV. Expectation is dashboard 1 will be shown then after 1 sec gap dashboard 2 will appear on screen then again pause for few seconds and dashbo... See more...
I have few Dashboards in splunk I want to play them on TV. Expectation is dashboard 1 will be shown then after 1 sec gap dashboard 2 will appear on screen then again pause for few seconds and dashboard 3 will come.   if not possible through splunk then how can I achieve this?  
Hi @isoutamo ,   I will do that next time I post, thank you.  I have checked the search and aside from the XXXXXX values being the address for the different vendors, each panel uses the exact same ... See more...
Hi @isoutamo ,   I will do that next time I post, thank you.  I have checked the search and aside from the XXXXXX values being the address for the different vendors, each panel uses the exact same search, it is just for 1 I get NULL values even though the messages are there when I look at the events
Thanx. Next time when you paste something please use </> code block to avoid character changes etc.  Based on those I suppose that your data haven't correct values what you are looking for. You shou... See more...
Thanx. Next time when you paste something please use </> code block to avoid character changes etc.  Based on those I suppose that your data haven't correct values what you are looking for. You should check it by clicking magnifying class on right bottom corner of your dashboard's individual panel. This opens exactly same search you to separate window/tab and you can see what events it found. Then you can debug it by e.g. commenting rows away from bottom to top. 
Here is the source code all together for those panels - left to right, might be easier to debug <row> <panel> <chart> <title>SchedConnect Messages to [nnnnn]</title> <search> <query>index="emh_... See more...
Here is the source code all together for those panels - left to right, might be easier to debug <row> <panel> <chart> <title>SchedConnect Messages to [nnnnn]</title> <search> <query>index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY | timechart count by DR1</query> <earliest>$TimePickerKielToken.earliest$</earliest> <latest>$TimePickerKielToken.latest$</latest> <refresh>1m</refresh> <refreshType>delay</refreshType> </search> <option name="charting.axisTitleX.text">Time</option> <option name="charting.chart">column</option> <option name="charting.drilldown">all</option> <option name="charting.legend.placement">right</option> <option name="refresh.display">progressbar</option> </chart> </panel> <panel> <chart> <title>SchedConnect Messages to {nnnnn]</title> <search> <query>index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYY | timechart count by DR1</query> <earliest>$TimePickerKielToken.earliest$</earliest> <latest>$TimePickerKielToken.latest$</latest> <refresh>1m</refresh> <refreshType>delay</refreshType> </search> <option name="charting.axisTitleX.text">Time</option> <option name="charting.axisTitleX.visibility">visible</option> <option name="charting.axisTitleY.visibility">visible</option> <option name="charting.axisTitleY2.visibility">visible</option> <option name="charting.chart">column</option> <option name="charting.drilldown">all</option> <option name="charting.legend.placement">right</option> <option name="refresh.display">progressbar</option> </chart> </panel> <panel> <chart> <title>SchedConnect Messages to [nnnnn]</title> <search> <query>index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY | timechart count by DR1</query> <earliest>$TimePickerKielToken.earliest$</earliest> <latest>$TimePickerKielToken.latest$</latest> <refresh>1m</refresh> <refreshType>delay</refreshType> </search> <option name="charting.axisTitleX.text">Time</option> <option name="charting.chart">column</option> <option name="charting.drilldown">all</option> <option name="refresh.display">progressbar</option> </chart> </panel>
here is the source for the 1st panel <row> <panel> <chart> <title>SchedConnect Messages to [nnnnn]</title> <search> <query>index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY | t... See more...
here is the source for the 1st panel <row> <panel> <chart> <title>SchedConnect Messages to [nnnnn]</title> <search> <query>index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY | timechart count by DR1</query> <earliest>$TimePickerKielToken.earliest$</earliest> <latest>$TimePickerKielToken.latest$</latest> <refresh>1m</refresh> <refreshType>delay</refreshType> </search> <option name="charting.axisTitleX.text">Time</option> <option name="charting.chart">column</option> <option name="charting.drilldown">all</option> <option name="charting.legend.placement">right</option> <option name="refresh.display">progressbar</option> </chart> </panel> <panel> <chart>
Here is the source for the 2nd panel <chart> <title>SchedConnect Messages to {nnnn]</title> <search> <query>index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY | timechart count by... See more...
Here is the source for the 2nd panel <chart> <title>SchedConnect Messages to {nnnn]</title> <search> <query>index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY | timechart count by DR1</query> <earliest>$TimePickerKielToken.earliest$</earliest> <latest>$TimePickerKielToken.latest$</latest> <refresh>1m</refresh> <refreshType>delay</refreshType> </search> <option name="charting.axisTitleX.text">Time</option> <option name="charting.axisTitleX.visibility">visible</option> <option name="charting.axisTitleY.visibility">visible</option> <option name="charting.axisTitleY2.visibility">visible</option> <option name="charting.chart">column</option> <option name="charting.drilldown">all</option> <option name="charting.legend.placement">right</option> <option name="refresh.display">progressbar</option> <option name="trellis.enabled">0</option> <option name="trellis.size">medium</option> </chart> </panel> <panel> <chart>
This is panel 2 [the one showing NULL]  
This is panel 1  
Are you sure that those queries are used on those panels? Or are there some other filtering after those queries which remove all results? Can you share those panels source and also your sample data ... See more...
Are you sure that those queries are used on those panels? Or are there some other filtering after those queries which remove all results? Can you share those panels source and also your sample data (with anonymous values when needed)?
OK. Yes.  I found it. https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/PropagateSHCconfigurationchanges#Set_up_the_deployer "Deploy to multiple clusters The deployer sends the same c... See more...
OK. Yes.  I found it. https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/PropagateSHCconfigurationchanges#Set_up_the_deployer "Deploy to multiple clusters The deployer sends the same configuration bundle to all cluster members that it services. Therefore, if you have multiple search head clusters, you can use the same deployer for all the clusters only if the clusters employ exactly the same configurations, apps, and so on. If you anticipate that your clusters might need different configurations over time, set up a separate deployer for each cluster." But honestly,  I can't think of any reasonable use case for this.
Thanks but neither of those seem to work, I still get NULL even though there are messages.  This is very frustrating  
Did the installation verification gives any other reason why it couldn't succeed? But as already said, you must create a support ticket.
Based on documentation this is supported configuration. There could be several SHC serving by one deployer, but all those SHCs must have an equal configuration. Of course they can have different amoun... See more...
Based on documentation this is supported configuration. There could be several SHC serving by one deployer, but all those SHCs must have an equal configuration. Of course they can have different amount of members and those size could be different in every SHC. But honestly said I couldn't find any real use cases for this. Only one which comes my mind is that those SHC:s have different user bases and some configuration are managed with SHC GUI (which is not wise). Definitely it's better and easier way that every SHC has it's own Deployer. Using one Deployer with several SHCs will be road to issues.
Here is your original search  index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY | timechart count by DR1 You should do it like index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX... See more...
Here is your original search  index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY | timechart count by DR1 You should do it like index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY DR1=* | timechart count by DR1 or index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY | eval DR1 = coalesce(DR1, "DR1 N/A") | timechart count by DR1  https://docs.splunk.com/Documentation/Splunk/9.4.0/SearchReference/ConditionalFunctions#coalesce.28.26lt.3Bvalues.29  
Here is the events from left to right for the 3 panels. So here the DR1 is not showing but the 1st and 3rd panels work but the middle one does not.  The characters in the RED box is what the... See more...
Here is the events from left to right for the 3 panels. So here the DR1 is not showing but the 1st and 3rd panels work but the middle one does not.  The characters in the RED box is what the DR1 is looking for either SSM or ASM
Hi @gcusello ,   Thanks for the quick reply!  I am new to this, where would I add the DR1=* in my search?   Also not all the panels have the DR1 in there events but they still work.  This is part... See more...
Hi @gcusello ,   Thanks for the quick reply!  I am new to this, where would I add the DR1=* in my search?   Also not all the panels have the DR1 in there events but they still work.  This is part of why I don't understand why some work and not others.
Hi @DarrellR , are you sure that all the events have the DR1 field? you could try to add DR1=* to the main search. Ciao. Giuseppe