Dashboards & Visualizations

Dashboard Tables: Limiting the number of displayed rows

egerner
Engager

I am having an issue with some of the table options. I’d like to limit the table to 10 rows and then allow pagination. Here are my commands (simple xml):

 <option name="count">10</option>
 <option name="showPager">true</option>

While the pagination seems to be working, the count option doesn’t work at all – it defaults to displaying however many rows I had displayed in my saved search (ie, 50) and only does pagination after this point. Are my commands wrong, or is something else the problem? Any ideas?

Tags (2)

jbsplunk
Splunk Employee
Splunk Employee

This is being tracked as SPL-32968. The problem is regarding applying viewstate. When a search is saved, a copy of the current view state is made and stored in $SPLUNK_HOME/etc/users/admin/search/local/viewstates.conf. When the search is loaded, the configuration that is last applied is the viewstate and this is clobbering the XML defined "count" option.

This is going to be fixed in 4.2.3, for anyone who is interested.

0 Karma

hulahoop
Splunk Employee
Splunk Employee

Emily, you're right. The count option has no effect. The showPager option does. See if this workaround works for you:

  1. in the flash timeline view, set 'Results per page' to 10
  2. save your search as a new search (this associates a new viewstate with the paginator count as 10)
  3. use the new saved search in your dashboard.

Alternatively, you (or your Splunk Admin) can correct the viewstate:

  1. find the viewstate id associated with the saved search in savedsearches.conf (e.g. vsid=gp902hc2)
  2. find the viewstate using the vsid in viewstates.conf.
  3. edit the Count_#_#_#.default, MaxLines_#_#_#.default, MaxLines_#_#_#.maxLines variables.
  4. restart Splunk.

This is a bug, which I will file on your behalf. Thank you for bringing this to our attention. 🙂

mw
Splunk Employee
Splunk Employee

What is your search that renders the table? I've never experienced this, but my searches tend to be something like "... | table field1, field2". Are you using the table command or something else?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...