Recently upgraded to Splunk 6.5.0. I am trying to access the first row from the search result in a dashboard. In version 6.3.2, there was an event handler 'finalized' which provides access to the first row
Documentation from version 6.3.2 : http://docs.splunk.com/Documentation/Splunk/6.3.2/Viz/tokens#Define_search_tokens
But in 6.5.0 there is no 'finalized' handler. Only handlers available are progress, done, cancel, error, fail and none of those provide access to first row of the result
Documentation from version 6.5.0: http://docs.splunk.com/Documentation/Splunk/6.5.0/Viz/tokens#Define_search_tokens
Is there any workaround? Is it done differently in 6.5.0?
... View more