Splunk® Enterprise

Dashboards and Visualizations

Download manual as PDF

Download topic as PDF

Dashboards and forms

Use dashboards and forms to visualize, organize, and share data insights.

Dashboards and forms have one or more rows of panels. Each panel contains a visualization, such as chart, table, or map. In each panel, a search generates data for the visualization.

Forms are different from dashboards because they include <input> elements, such as text boxes or radio buttons, for user interactions. You can configure elements in a form, such as a panel, to respond to user input by customizing the searches that drive visualizations or changing other behavior.

For more details on building a <dashboard> or <form>, see the Simple XML Reference.


Anatomy of dashboards and forms

See the Simple XML Reference for complete information on dashboard and form element hierarchy.

Element Description
top-level element <dashboard> or <form>
Title <label> (Optional)
Description <description> (Optional)
Global search Global search is for use with post-process searches. Post-process searches have limitations. See Post-process limitations.

<search id="[identifier]">

Form inputs (Forms only) <fieldset>
  <input>
    <text>
    
Rows Each row contains one or more panels.

<row>

Panels Each panel contains an optional title, optional inputs, and one or more visualizations. See Dashboard panels for the types of panels available.

<panel>

Visualizations A visualization displays data returned from a search.

<chart> <event> <map> <single> <table>

Search A search for a visualization.

<search id="[identifier]"> Base search for post-process searches.

<search base="[id]"> Post-process search referencing a base search.

<search ref="[report] [ app="[app name]" ]> Reference a search from a report. Reference to app is optional.

Options Properties specific to a visualization.

<option name="[option name]">

PREVIOUS
Searches power dashboards and forms
  NEXT
Dashboard examples

This documentation applies to the following versions of Splunk® Enterprise: 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 7.0.0


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters