Build custom dashboards
The Splunk App for Windows Infrastructure has many dashboards which display the data that the app collects. New for this version, you can also build your own panels with what is known as Palette view. Palette view allows you to design, save, and later retrieve custom dashboard panels from within the app at any time, without having to know how to build the views using XML code. You can use any dashboard panel that the Splunk App for Windows Infrastructure has available.
The Splunk App for Windows Infrastructure enables the custom dashboard builder when you select "App Dashboards" or "App Palette" from the Builder menu.
The Splunk App for Windows Infrastructure provides several pre-built dashboard palettes. You can edit those palettes or create and customize new ones.
When you select "App Dashboards" from the Builder menu, the Splunk App for Windows Infrastructure loads the app dashboards screen.
The page lists all available dashboard palettes, sorted alphabetically. The page also lists the palette's owner and the last time it was updated, and offers you the ability to make a copy of it (if it is one of the pre-built palettes) or edit it.
To view a particular palette, click its name in the list. The Splunk App for Windows Infrastructure updates the screen to show you the dashboards that comprise the palette.
To edit a palette, click on the "Edit" or "Clone" link underneath the "Actions" column alongside the palette that you want to edit. The Splunk App for Windows Infrastructure loads the App Palette page.
Note: The action listed in the Actions column depends on whether or not the palette that you are attempting to edit is a pre-built page or a page that you have created or cloned. You cannot edit the pre-built pages, you can only clone them. Once you have cloned a pre-built page, you can edit the copy as much as you want.
To create a new dashboard palette, click the "Create New App Dashboard" button on the upper right corner of the page. The Splunk App for Windows Infrastructure loads the App Palette page.
View dashboard palette
In this view you can use the dashboard palette like you would any other dashboard in the Splunk App for Windows Infrastructure. You can:
- Click on links on the individual dashboards within the palette to get more information about the item you clicked.
- Filter events by using available drop-down menus or text entry boxes on a dashboard.
- Click trend lines to get more information about the events around the area you clicked.
- Sort individual lists within each dashboard by using the appropriate sorting buttons on the dashboard.
Edit dashboard palette
When you create a new palette or clone an existing one, the Splunk App for Windows Infrastructure loads the App Palette page.
In this page, you can create custom dashboard palettes by dragging dashboard panels and dropping them into the palette view. As you add panels, you can move them around to suit your taste. Then, you can save the palette with a name that you will remember and retrieve it later in the "App dashboards" page.
The App Palette page has two sections:
- The "Panels" section on the left side, which lists all available panels in the Splunk App for Windows Infrastructure. It has three drop-down boxes which let you select dashboard panels for Windows or Active Directory.
- The "Drop Zone" on the right side, where you drag, drop, and arrange dashboard panels.
Create a new palette
To create a new palette:
1. Enter the App Palette page by selecting "App Palette" under the "Builder" menu. The Splunk App for Windows Infrastructure loads the App Palette window.
2. In the Panels section, locate the dashboard panel that you want to add to the palette. You can do this in one of two ways:
- a. Type in the name of a dashboard in the text entry box above the three drop-down boxes. If you begin typing in a name, all panels which match the text you typed will appear. Or,
- b. Click on one of the drop-down boxes and locate the dashboard panel in the list.
3. Once you have found the panel you want to include in the palette, click the panel, then drag it from the Panel window to the Drop Zone. The Splunk App for Windows Infrastructure immediately updates the palette with the dashboard panel you added.
Important: You must hold down the left mouse button for the entirety of the click-and-drag operation.
4. To add more dashboard panels to the palette, repeat Steps 2 and 3.
5. Once you have added the panels you want, you can then arrange them in a way that makes sense to you.
- a. Move your mouse pointer onto the top of the panel you want to move.
- b. Hold down the left mouse button and drag the panel to the place you want it to go. The Splunk App for Windows Infrastructure updates the screen and moves the Drop Zone toward this area.
- c. Once the panel is in the updated Drop Zone, release the mouse button. The Splunk App for Windows Infrastructure updates the page to reflect the rearranged panels.
Note: You can hide the Panels section to provide additional screen space to move dashboard objects around. To toggle the display of the Panels section, click the "Panels" button.
6. To remove dashboard panels that you do not want:
- a. Move your mouse pointer onto the top of the panel you want to delete.
- Each panel has a "handle bar" which allows you to move the panel around. When the mouse cursor is on a panel's handle bar, it turns into a cross shape and the handle bar activates, displaying an "X" just to the right of the panel's name.
- b. Place the mouse cursor on the "X" and click once to remove the panel.
- c. Alternatively, you can remove all panels you have added by clicking Clear in the upper right corner of the page.
7. Once you have rearranged the panels, save the palette by clicking Save As... in the upper right corner of the page. The Splunk App for Windows Infrastructure presents the "Save As..." dialog box.
8. Enter a title whose name you will remember in the Title field and a description of the palette in the Description field. The Splunk App for Windows Infrastructure automatically generates a palette ID that it bases on the text you entered in the "Title" field.
Note: You can override the suggested ID with an ID of your choosing by entering it into the ID field.
9. Click Save to save the palette. The Splunk App for Windows Infrastructure saves the palette and returns you to the App Palette window.
Edit an existing palette
To edit an existing palette:
1. From the App Dashboards page, choose the dashboard palette that you want to edit and click either Edit or Clone under the Actions column. The Splunk App for Windows Infrastructure loads the App Palette window and populates the Drop Zone with the palette's existing panels.
2. Add or remove dashboard panels as desired. Refer to "Create a new palette" above for instructions on how to add and remove individual panels. To remove all dashboard panels, click the "Clear" button at the upper right corner of the page.
3. Arrange dashboard panels as desired in the palette window.
4. If you want to change the description of the palette, click the "Details" button in the upper right corner of the page, and in the pop-up menu that appears, select "Edit Description". The Splunk App for Windows Infrastructure presents the "Edit App Dashboard Details" dialog box, where you can change the name, description and ID of the dashboard palette.
4. If you want to delete the palette, click the "Details" button, and in the pop-up menu that appears, click "Delete App Dashboard". The Splunk App for Windows Infrastructure asks you if you are sure that you want to delete the page. To confirm, click the "Delete" button in this dialog box.
5. If you want to clone the palette, click the "Details" button, and in the pop-up menu that appears, click "Clone App Dashboard". The Splunk App for Windows Infrastructure clones the page and returns you to the App Palette window where you can edit and save changes to the cloned palette.
6. After you are satisfied with the changes, save the palette by clicking on the "Save" button in the upper right corner of the App Palette page.
Active Directory Help
Active Directory Reports
This documentation applies to the following versions of Splunk® App for Windows Infrastructure: 1.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4