Dashboards & Visualizations

How to display charts on a dashboard based on the drop-down form input?

jimyliu
Explorer

I have a dashboard using the form with list of apps as input(ex: appA, appB, appC, appD) as the drop down list.
The form has 4 charts,(ex: chart cpu, chart memory, chart response time, chart http 5xx error count).
If the user pick appA, then display only cpu , memory and respond time charts.
if user pick appB, then display only cpu, memory and http 5xx error count.

Is there a simple way to do that (if condition(app=appA) to decide if I want to display each chart ) like regular coding . Thanks

Jim

1 Solution

MuS
Legend

Hi jimyliu,

you can do something like this in the Sideview module called Switcher. Install the App and open this link:

http://YourSplunkServerHostNameHere:YourSpunkWebPortHere/en-US/app/sideview_utils/switcher1_with_pul...

hope this helps to get you started ...

cheers, MuS

View solution in original post

MuS
Legend

Hi jimyliu,

you can do something like this in the Sideview module called Switcher. Install the App and open this link:

http://YourSplunkServerHostNameHere:YourSpunkWebPortHere/en-US/app/sideview_utils/switcher1_with_pul...

hope this helps to get you started ...

cheers, MuS

jimyliu
Explorer

Hi,

I am able to use side view switcher. in my dashboard, I set the refresh=300 to reload the page every 5 mins. By default, the dashboard shows appA's charts. When I switched to appB's charts, after 5 mins, the the whole page refreshed, it still show appA's charts. Is there a way to let the page remembered what I have switched to after the refresh?

Thanks!

jimy

0 Karma

jimyliu
Explorer

thanks, will try it. I am not the admin for our splunk server. but will check with them.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...