Splunk® Enterprise

Dashboards and Visualizations

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Edit visualizations

Edit a visualization to configure its search, type, appearance, and behavior. You can edit visualizations from the Dashboard Editor or on the Search page. In either location, you can adjust the following visualization components.

Visualization components Description
Search string Use the dashboard search editor or the search bar to change the query driving the visualization.
Type Use the Visualization Picker to select a visualization type. Ensure that the query generates results in the proper structure for the selected visualization.
Format and behavior Use the Format menu to adjust appearance, drilldown, and other settings for the visualization's user interface.

Formatting and other options vary by visualization type. To compare visualizations, see the Visualization reference. For details on writing queries for different visualizations, see Data structure requirements for visualizations.

For information on using Pivot to edit visualizations, see Design pivot charts and visualizations with the Pivot Editor.

Visualization editing workflow

The workflow for editing a visualization search, type, or format is slightly different depending on whether you use the Dashboard Editor or the Search page.

Dashboard Editor

  1. In the Search and Reporting app, select the Dashboards tab.
  2. Locate the dashboard to edit. Use one of the following options.
    Option Additional steps for this option
    Select Edit > Edit Panels. None
    Click on the dashboard name to view it. After the dashboard opens, select Edit > Edit Panels.
  3. In the panel you are editing, locate the icons for editing the search, visualization type, and format. Select the icon for the component you are editing.
  4. Edit the selected visualization component.

Dashboard editing permissions
Write permission is required for editing dashboard panels. By default, you have write permission for any dashboard that you create. However, you might have read-only access to other dashboards. Admins may change editing permissions.

Search page

  1. In the Search and Reporting app, select the Search tab.
  2. Enter a query.
  3. When results are available, select the Visualization tab.
  4. To edit the visualization, use one of the following tools.
    Tool Description
    Visualization Picker Change the visualization type.
    Format menu Change the visualization format and behavior. Format options vary by visualization type.
    Search bar Edit the query and rerun it to refresh the visualization.

Using the Format menu

Format menu configurations are applied immediately to visualizations.

  • Each edit that you make is saved to the visualization. You can see each change in the visualization and make adjustments as you go.
  • Edits are reflected in the dashboard Simple XML source code as they are made.
  • Click and drag the Format menu to move it anywhere on the screen.
  • Close the Format menu or click anywhere outside of it to exit and save changes.

Configuration options

Each visualization has a set of configuration properties. These properties define the visualization's user interface. From a dashboard or the Search page, use the Format menu to adjust these properties and change appearance or behavior.

For more details on visualization properties, see

Last modified on 10 June, 2016
Create and edit forms with the Dashboard Editor
Convert a dashboard to HTML

This documentation applies to the following versions of Splunk® Enterprise: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters