I'm also struggling with this. I've followed Splunk's example, even naming all my fields the same but with zero success. https://docs.splunk.com/Documentation/DashApp/0.9.0/DashApp/dsSec#Annotation_example Their documents also conflict on where the annotation options should go. In the example, its in a "encoding" stanza, in their Dashboard Studio docs, suggests they below in "options" Tried both, no annotations. Sorry I have no help but thought maybe you hadn't added seen the requirement for the options.
... View more