Splunk® Enterprise

Dashboards and Visualizations

Splunk Enterprise version 7.3 is no longer supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.

Dashboard overview

Create new dashboards or edit existing ones.

For a quick glance at the most common use cases and commands for creating dashboards, note that you can access the Splunk Dashboards Quick Reference guide by clicking the link in Getting started.

The dashboard and form workflow

Working with dashboards includes one or more of the following tasks.

Build dashboards

  • Create a new dashboard
  • Add new visualizations to a dashboard

For more information on building dashboards, see Create a dashboard

Edit dashboards

  • Add a panel to a dashboard
  • Edit dashboard panels and panel visualizations
  • Manage dashboard searches

For more information on editing dashboards, see Edit dashboards

Convert a dashboard to a form

  • Add user inputs to a dashboard to convert it to a form
  • Edit forms
  • Work with user input settings

For more information on forms, see Create and edit forms

Customize Simple XML

  • Edit Simple XML source code to customize a dashboard or form.

For more information on using Simple XML, see Editing Simple XML

Add interactive and dynamic behavior

  • Use tokens to capture and transfer data.
  • Add event handlers to implement dynamic behavior.

For more information on event handlers and tokens, see Use drilldown for dashboard interactivity and Token usage in dashboards

Tools and frameworks

To build and edit dashboards, use one or more of the following tools and frameworks.

Dashboard editor user interface

Build and edit dashboards using the Splunk Web user interface.

Simple XML

Dashboards use Simple XML source code to define their content and behavior. You can use the dashboard editor in Splunk Web to edit this source code.

To learn more, see Editing Simple XML.

Developer options

Splunk Enterprise users can implement additional dashboard customizations with Dashboard Studio, which autogenerates source code from the UI that you can then modify.

For more information, see the following Splunk developer portal resources.

Splunk will deprecate support for HTML dashboards in the near future. Splunk does not recommend converting Simple XML dashboards to HTML.

Deprecated options

The following dashboard framework options are deprecated as of version 6.3.0:

  • Advanced XML
  • Module System (Deprecated as part of Advanced XML).

For information on other customization options, see: Building customizations for the Splunk platform

Removed options

The following dashboard framework options is removed as of version 7.3.0.

Option For more information see
Django Bindings Removed features in the Splunk Enterprise 7.3.0 Release Notes.
Last modified on 13 February, 2024
Use trellis layout to split visualizations   About the dashboard editor

This documentation applies to the following versions of Splunk® Enterprise: 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 9.4.0, 7.3.1, 7.3.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters