Dashboards & Visualizations

using search result output to set title of panel in simple xml

ektasiwani
Communicator

Hyee,

I have some 12 hour data in XML file and i am using that data to plot graph in splunk dashboard.
I want to set the time for which i have first available data as title.

How to get this? i don't want to create any drop down or input field or radio field to set token.
Is there any other way to set token?

Or is there any other way to achieve this.

Thanks

Tags (2)
0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

You can add a "Single Value" panel to the dashboard, use the search for the graph as the base, and select only the time field.

<row>
    <panel>
    <single_value>
       <search base="my_search"><query>fields myTime</query></search>
    </single_value>
     <chart>
     <search id="my_search"><query>......</query></search>
     </chart>
 </panel>
 </row>

View solution in original post

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

You can add a "Single Value" panel to the dashboard, use the search for the graph as the base, and select only the time field.

<row>
    <panel>
    <single_value>
       <search base="my_search"><query>fields myTime</query></search>
    </single_value>
     <chart>
     <search id="my_search"><query>......</query></search>
     </chart>
 </panel>
 </row>
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...