Building a form-based dashboard
The first part of a form-based dashboard is deciding which inputs our users will care about, and usually this starts with the time range picker module.
Let's create a dashboard out of the report we made earlier from Linux df
data. When we open up our report, we notice that there is a useful option in the top right-hand section Add to Dashboard:
When we click on that button we get this popup, and we have to choose a name for it:
In this case, I choose myFirstDashboard
, and click Save.
On the next popup, just click View Dashboard and Splunk will take you right to it.
Now we understand that our report gives us data for a single day on all machines, and some of our users would like to be able to see data for last week as well, as only a single host is experiencing errors.
The easiest way to do this is by adding the time range picker, and a Text module, then set their tokens to be passed down to the original search. This will allow the user to select the...