Splunk® Light (Legacy)

Search and Reporting Examples

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Add a dashboard panel from a search

To visualize your data, you first need to execute a search. Splunk software provides visualizations that together suit all types of data. In this scenario, search for all processes that are running under the root user.

  1. Click Search in the Splunk Light bar.
  2. Type the following into the search bar.

    sourcetype=ps user=root

    You now see all processes that are running under the root user.
  3. Click Save As.
  4. Click Dashboard Panel.
  5. Add your list of events to your existing dashboard.
  6. Name your panel Processes running under the root user.
  7. Click Save.
  8. To view your changes, click View Dashboard.

Your dashboard now contains three panels: two prebuilt panels, and one powered by an inline search.

Last modified on 10 August, 2016
PREVIOUS
Add prebuilt panels to a dashboard
  NEXT
Add tables to a dashboard

This documentation applies to the following versions of Splunk® Light (Legacy): 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.5.1612 (cloud service only), 6.6.0, 6.6.1, 6.6.2, 6.6.3, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters