All Apps and Add-ons

Sideview Utils ReportBuilder

bnerella
Engager

I need help on how I can make my extracted field in my Indexed data show in the Chart Drop Down menu in Sideview Utils. Now, I can only chart with the default field that were automatically extracted by splunk.

0 Karma

sideview
SplunkTrust
SplunkTrust

Most likely the field extraction is defined only in some other app, and the Sideview Report builder is also by default available only in the Sideview Utils app.

If that's the case you have two solutions --

1) globally export all the config for the field extractions and fields and lookups that you want to be able to use in the Sideview Report Builder. This might be just one field extraction or it might be quite a lot of different types of things.

OR

2) export the Report Builder view to the system level. This will make it appear in the app navigation of many apps of course, and since many would find this disruptive we don't ship it exported like that.

From the Sideview Utils homepage, click "settings" in the top right, then go to "Settings > User Interface > Views" (If you're in 5.X or earlier, you want "Manager > User Interface > Views")

Then find the "sv_report" view in the table and click the "permissions" link. Then set the radio button to "All apps" and submit.

NOTES:
do not touch any view called "report". As of several Sideview Utils versions ago the Sideview "report" view was renamed to "sv_report" to avoid collisions with a new view in Splunk 6 that is also called "report".

And it goes without saying that you should be on the latest Sideview Utils. The latest is 3.2, released just this week, and as it happens contains an improvement that can greatly speed up the rendering of the pulldowns in the Report Builder. 😃

Get the latest Sideview Utils for free from: http://www.sideviewapps.com/apps/sideview_utils

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...