# Do dashboard filters/variables exist?

**URL:** <https://community.graylog.org/t/do-dashboard-filters-variables-exist/23027>\
**Category:** Graylog Central (peer support)\
**Created:** [March 14, 2022, 2:58pm UTC](https://community.graylog.org/t/do-dashboard-filters-variables-exist/23027 "2022-03-14T14:58:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![samf](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/samf/32/10850_2.png) [@samf](https://community.graylog.org/u/samf)\
**Post date:** [March 14, 2022, 2:58pm UTC](https://community.graylog.org/t/do-dashboard-filters-variables-exist/23027/1 "2022-03-14T14:58:28Z")

</div>

Hi folks,

Forgive me if I’ve missed docs, I believe this just isn’t supported but would like to be sure.

I am trying to create dashboards that will be used across multiple clients (all logs aggregate to our server) but can’t see a way to filter a dashboard.

I was hoping for something like Grafana where you can add a dropdown (or just a free entry textbox) where you select a specific value, ie “Client1” and it filters the data.

I would also be happy with just being able to add something to the query being used in the individual widget/panels.

Ie I would add enter “AND client = 1” into a field and this would be appended to the query on all the widgets.

This seems a pretty basic thing to me to help you drill down on issues etc but is this just not a use case other people have?

Thanks!

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [March 14, 2022, 5:28pm UTC](https://community.graylog.org/t/do-dashboard-filters-variables-exist/23027/2 "2022-03-14T17:28:59Z")

</div>

You may be looking for something like [Search Parameters](https://docs.graylog.org/docs/parameters)? It requires an Enterprise License but as long as you keep your logs \< 2GB you can have one for [free](https://www.graylog.org/downloads/free-enterprise)…

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [March 15, 2022, 12:24am UTC](https://community.graylog.org/t/do-dashboard-filters-variables-exist/23027/3 "2022-03-15T00:24:40Z")

</div>

Hello @samf

Just chiming in on this statement.

> [@samf](#):
>
> Ie I would add enter “AND client = 1” into a field and this would be appended to the query on all the widgets.

Depending on how the Widget is configure, Here are some examples in my lab querying by “source”.

**Example:**  
Dashboard “Central Command Unit Section” with Aggregating count by source.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/d/d8aee2ced519c2623f7ca87a117f2012f0d58965.png)

Let’s say I want to add a quick filter on device called **veam**. Click the down arrow next to the name and select " add to query"

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/f/f83d5b58b96c7458f7b0bf631e00dbb64f5b8e9b.png)

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/a/aa93bb3d40ab98ba1e4280abf3ffb3dc19086941.png)

**Next example:**

Dashboard “Central Command Unit Section” with Aggregating count by source called “veam”

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/a/aa93bb3d40ab98ba1e4280abf3ffb3dc19086941.png)

and I want to add a different device call keycloak.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/15ce5180f641f65db8e4435a53fac867d0bb205b.png)

**Next example :**  
Widget made for trending data on **veeam** device only, so I configured this widget like so…

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/145c21e1330a6aed694681e09191c23270ffe045.png)

Dashboard looks like this…

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/b/b3e3a78ea5783a9f9d5c0b69b4399876fdf2de8f.png)

adding new device Keycloak to widget.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/d/d38942bff3f99258b7b69a2a9268af4e4af6ba82.png)

Only other way I know how to add info is what @tmacgbay suggested above.

---

<div class="post-metadata">

**Author:** ![samf](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/samf/32/10850_2.png) [@samf](https://community.graylog.org/u/samf)\
**Post date:** [March 15, 2022, 11:45am UTC](https://community.graylog.org/t/do-dashboard-filters-variables-exist/23027/4 "2022-03-15T11:45:33Z")

</div>

Thanks this is the behaviour I’ve already seen, unfortunately we are bringing in a lot of logs from disparate sources and in different formats so I’m not sure this is appropriate! I think the enterprise Search Parameter feature is probably what we need.

I really appreciate the suggestion though!

---

<div class="post-metadata">

**Author:** ![samf](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/samf/32/10850_2.png) [@samf](https://community.graylog.org/u/samf)\
**Post date:** [March 15, 2022, 11:49am UTC](https://community.graylog.org/t/do-dashboard-filters-variables-exist/23027/5 "2022-03-15T11:49:28Z")

</div>

That is 100% what I’m looking for, thank you!

I’m hesitant to tie into something that requires staying too low though, we are (slowly but surely) building this out as a scalable solution to address a lot of clients. \<2GB might be practical now but it hopefully won’t be long term. I’ll drop sales a line when I have time and see whether the lowest tier might be manageable.

Thanks for your help and suggestion!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [March 29, 2022, 11:50am UTC](https://community.graylog.org/t/do-dashboard-filters-variables-exist/23027/6 "2022-03-29T11:50:03Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
