Hi Team,
Please help us on the dashboard issue, we have a splunk xml dashboard table as shown in the below snippet.
In the root cause column the entire event is coming . We need help so that the entire event should be adjusted to 4 lines and if required the column width can extend as per the event.
Here I suggest displaying the trimmed value in table view and displaying the full value by expanding the table row.
This is a sample search for trimming value.
| makeresults | eval A="a
b
c
d
e
f
g
h
"
| rex field=A "(?<displayA>^.*\n.*\n.*\n.\n)"
And this is an example of "How to use Row expansion"
Let me know if you need more help on this.
Thanks
KV
If any of my replies help you to solve the problem Or gain knowledge, an upvote would be appreciated.