Hello Fellow Splunkers,
I am fairly new to Splunk , so apologies in advance if this is a silly question. I have a specific task that I am trying to achieve and I want to use basic xml. I know this can be done through advanced xml and sideviewutils but i want to stick to basic xml if possible.
My requirement:
I have a certain log file and I have defined several Eventtypes. I am also extracting several fields, specific to each Eventtype. I am attempting to display the top eventtypes in chart and table format and then for each of the event types, I run several searches displaying bar charts, pie charts and tables. The number of sub searches for the eventtypes would vary depending on the eventtype.
Question:
I have gone through the Splunk 6 Dashboard examples, and I am thinking of using the Link Switcher. The problem is that the data-items in my case is not static, it will be dynmaic based on the top eventtypes. So will the Link Switcher take a search result instead of statically defining them ?
I have used Sideviewutils Tabs Module and Switcher Module to achieve the same but I am wondering if there is way to do this in basic xml. I have gone through the documentations, previous posted questions, etc, Unable to find any. Any help would be appreciated !
Thanks