Dashboard Studio: More Maps & More Interactivity

In Splunk Cloud Platform 8.2.2203, we're continuing to expand on interactivity capabilities and visualizations for Dashboard Studio. We've added the ability to use search results and job metadata as tokens, and pass tokens through drilldowns to other dashboards. There is a new map visualization for cluster maps and UI to match strings for dynamic coloring. And finally, we've included the ability to set a Studio dashboard as your home dashboard.

Use Search Results or Search Job Metadata as Tokens

Since Dashboard Studio's inception, you have been able to set tokens using inputs. In Splunk Cloud Platform 8.2.2109, we introduced the ability to set tokens by clicking on visualizations. Now, we're adding a third way to set tokens: from search results or search job metadata!

This will unlock more use cases such as setting up default dashboard values on dashboard load, and dynamic text.

In order to enable a data source to use its results or metadata as token values, be sure to check the option in the data source configuration panel:

The syntax generally follows the format: $search name:job.<metadata>$. In the example above, in order to retrieve job status for my data source, "Activity by Sourcetype", I used the following token: $Activity by Sourcetype:job.status$. If I wanted to render my search results directly in my dashboard, I could use the syntax $search name:result.<fieldname>$ to render the first row of the specified field. In this scenario, I could use $Activity by Sourcetype:result.count$, which would render the first row of the 'count' field.

Pro tip: These tokens are case sensitive!

For a full list of the metadata you can use and proper syntax, check out our docs.

Drilldown to Other Dashboards (and Pass Tokens!)

We know that being able to drilldown to other dashboards and pass token values to maintain context is a key part of many workflows. In this release, we're introducing the ability to do just that. You can now set up a drilldown to "Link to Dashboard" and pass dynamic tokens (i.e. tokens values set by clicking on a visualization).

If the target dashboard has inputs with tokens, you'll see a list of the token names when configuring the dropdown. You can always manually specify the token name as well.

New Map for Bubble and Marker Maps

This release also comes with a new visualization: splunk.map which will enable you to display bubble and marker maps on the dashboard. This bubble map example uses the traditional geostats command.

You can also use a table command for map data, as shown in this marker map.

Match Strings for Dynamic Coloring

In addition to dynamic coloring based on numerical ranges, you can now apply dynamic coloring based on string or numeric matches.

You can find the string match UI in the Dynamic Coloring section of the configuration panel, under "Matches". This applies to all visualizations that support dynamic coloring: Single Value, Single Value Radial, Single Value Icon, Table, Choropleth SVG, Ellipse, Rectangle, and Sankey.

Set Studio Dashboards as Your Home Dashboard

We regularly review Splunk Ideas and add those requests to our backlog. One of the most recent examples of this is the idea to set Studio dashboards as home dashboards. And now you can do so! You can select a Studio dashboard for you home dashboard in three places:

From the home page

From the dashboard listing page

From the Studio dashboard

Coming Soon

Check out Dashboard Studio and send in your feedback through Splunk Ideas, and you might see your feature request listed on a future blog's "coming soon" list! We are continuing to work on new capabilities, which are delivered incrementally with Splunk Cloud Platform and Splunk Enterprise releases.

Helpful Resources

* This information is subject to change at any time, at the sole discretion of Splunk LLC and without notice. This roadmap information shall not be incorporated into any contract or other commitment. Splunk undertakes no obligation to either develop or deliver any product, features, or functionality described here.

Related Articles

Announcing the General Availability of Splunk POD: Unlock the Power of Your Data with Ease
Platform
2 Minute Read

Announcing the General Availability of Splunk POD: Unlock the Power of Your Data with Ease

Splunk POD is designed to simplify your on-premises data analytics, so you can focus on what really matters: making smarter, faster decisions that drive your business forward.
Introducing the New Workload Dashboard: Enhanced Visibility, Faster Troubleshooting, and Deeper Insights
Platform
3 Minute Read

Introducing the New Workload Dashboard: Enhanced Visibility, Faster Troubleshooting, and Deeper Insights

Announcing the general availability of the new workload dashboard – a modern and intuitive dashboard experience in the Cloud Monitoring Console app.
Leading the Agentic AI Era: The Splunk Platform at Cisco Live APJ
Platform
5 Minute Read

Leading the Agentic AI Era: The Splunk Platform at Cisco Live APJ

The heart of our momentum at Cisco Live APJ is our deeper integration with Cisco, culminating in the Splunk POD and new integrations, delivering unified, next-generation data operations for every organization.
Dashboard Studio: Token Eval and Conditional Panel Visibility
Platform
4 Minute Read

Dashboard Studio: Token Eval and Conditional Panel Visibility

Dashboard Studio in Splunk Cloud Platform can address more complex use cases with conditional panel visibility, token eval, and custom visualizations support.
Introducing Resource Metrics: Elevate Your Insights with the New Workload Dashboard
Platform
4 Minute Read

Introducing Resource Metrics: Elevate Your Insights with the New Workload Dashboard

Introducing Resource Metrics in Workload Dashboard (WLD) – a modern and intuitive monitoring experience in the Cloud Monitoring Console (CMC) app.
Powering AI Innovation with Splunk: Meet the Cisco Data Fabric
Platform
3 Minute Read

Powering AI Innovation with Splunk: Meet the Cisco Data Fabric

The Cisco Data Fabric brings AI-centric advancements to the Splunk Platform, seamlessly connecting knowledge, business, and machine data.
Remote Upgrader for Windows Is Here: Simplifying Fleet-Wide Forwarder Upgrades
Platform
3 Minute Read

Remote Upgrader for Windows Is Here: Simplifying Fleet-Wide Forwarder Upgrades

Simplify fleet-wide upgrades of Windows Universal Forwarders with Splunk Remote Upgrader—centralized, signed, secure updates with rollback, config preservation, and audit logs.
Dashboard Studio: Spec-TAB-ular Updates
Platform
3 Minute Read

Dashboard Studio: Spec-TAB-ular Updates

Splunk Cloud Platform 10.0.2503 includes a number of enhancements related to tabbed dashboards, trellis for more charts, and more!
Introducing Edge Processor for Splunk Enterprise: Data Management on Your Premises
Platform
2 Minute Read

Introducing Edge Processor for Splunk Enterprise: Data Management on Your Premises

Announcing the introduction of Edge Processor for Splunk Enterprise 10.0, designed to help customers achieve greater efficiencies in data transformation and improved visibility into data in motion.