Build a view
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
Build a view
Here's a basic overview on how to build a dashboard. You can build a dashboard within an existing App, or you can build a new App to house your dashboard and other views.
Build a new App
If you're starting out a new App, start here:
- Create your app workspace with app builder.
- The simplest way to build a new App is to start with app builder.
- Read through the app builder instructions and pick the app_sample template.
- Index relevant data.
- If you haven't already, get your data into Splunk. Set up data inputs for the data you want to index. Optionally send your data to an app-specific index, or send it to the default index if you don't want to segregate it.
Configure a new view
If you already know which app you want to add your dashboard to, start here:
- Add knowledge objects.
- Saved searches and reports are useful for any dashboard. Learn more about how to configure saved searches for your App.
- Add other knowledge objects, like event types, fields and tags. Learn more about knowledge objects in the Knowledge Manager Manual.
- Build your view.
- If you're just starting out and want to do something quick, create a simple dashboard.
- If you're comfortable with XML, build a more sophisticated dashboard.
- Most dashboards reference either ad-hoc searches or saved searches, so make sure you're familiar with the searches you've built.
- You can also include web resources in your dashboard.
- Set permissions on your dashboards.
- Decide if you want to let users customize the saved searches, charts and other elements in your dashboards. Your app users can always create objects within their own private directories, but you may want to let them share any objects they create at the app level.
- Set app permissions by following these instructions.
- Note that you must make your dashboard objects -- saved searches and such -- readable to any user who has access to that dashboard, or the searches will not display.
This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.