Splunk search for Most viewed dashboards
Copy
index="_internal" source=*access.log user!="-" */app/*
| rex field=_raw "/en-US/app/(?<app>[^/]+)/(?<dashboard>[^?/\s]+)\sHTTP" | stats count by dashboard, app | rename dashboard as "Dashboard Title", app as "App", count as Visits | sort - Visits | head 10
This Splunk search will provide a table showing the 10 most viewed dashboards within your Splunk environment. The search will return the title of the dashboard, what app it belongs to, and a count of how many times it has been visited during the search timeframe.