<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: host drop down in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684733#M19182</link>
    <description>&lt;P&gt;Here is another page that pretty much shows you how to do this&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Viz/Buildandeditforms" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/Viz/Buildandeditforms&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Apr 2024 00:36:57 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2024-04-19T00:36:57Z</dc:date>
    <item>
      <title>host drop down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684555#M19162</link>
      <description>&lt;P&gt;We want to add a host drop down in a dashboard&amp;nbsp; please find the host details below.&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%" height="69px"&gt;dev1&lt;/TD&gt;&lt;TD width="50%" height="69px"&gt;appdev1host&lt;BR /&gt;logdev1host&lt;BR /&gt;cordev1host&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="69px"&gt;dev2&lt;/TD&gt;&lt;TD width="50%" height="69px"&gt;&amp;nbsp;appdev2host&lt;BR /&gt;logdev2host&lt;BR /&gt;cordev2host&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="69px"&gt;dev3&lt;/TD&gt;&lt;TD width="50%" height="69px"&gt;appdev3host&lt;BR /&gt;logdev3host&lt;BR /&gt;cordev4host&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="69px"&gt;dev4&lt;/TD&gt;&lt;TD width="50%" height="69px"&gt;appdev4host&lt;BR /&gt;logdev4host&lt;BR /&gt;cordev4host&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="69px"&gt;sit1&lt;/TD&gt;&lt;TD width="50%" height="69px"&gt;appsit1host&lt;BR /&gt;logsit1host&lt;BR /&gt;corsit1host&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="69px"&gt;sit2&lt;/TD&gt;&lt;TD width="50%" height="69px"&gt;appsit2host&lt;BR /&gt;logsit2host&lt;BR /&gt;corsit2host&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="69px"&gt;sit3&lt;/TD&gt;&lt;TD width="50%" height="69px"&gt;appsit3host&lt;BR /&gt;logsit3host&lt;BR /&gt;corsit3host&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="69px"&gt;sit4&lt;/TD&gt;&lt;TD height="69px"&gt;appsit4host&lt;BR /&gt;logsit4host&lt;BR /&gt;corsit4host&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;drop down in dashboard should&amp;nbsp; have only 8 drop downs .&lt;BR /&gt;For example: if i choose dev1 it should capture all the hosts mentioned for dev1(appdev1host,&amp;nbsp;logdev1host,cordev1host)&lt;BR /&gt;&lt;BR /&gt;dev1&lt;BR /&gt;dev2&lt;BR /&gt;dev3&lt;BR /&gt;dev4&lt;BR /&gt;sit1&lt;BR /&gt;sit2&lt;BR /&gt;sit3&lt;BR /&gt;sit4&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 18:54:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684555#M19162</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2024-04-17T18:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: host drop down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684584#M19166</link>
      <description>&lt;P&gt;Have you added the dropdown - what is the problem you are facing?&lt;/P&gt;&lt;P&gt;Simply add the dropdown, set the 8 static options and then in your search use&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=bla host=*$my_host_token$*&lt;/LI-CODE&gt;&lt;P&gt;where my_host_token is the token for your dropdown&lt;/P&gt;&lt;P&gt;Assuming the table below is the finite list of hosts you will have, then this should work - there are of course other ways to do this, but this is the simplest.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 22:53:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684584#M19166</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-04-17T22:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: host drop down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684676#M19169</link>
      <description>&lt;P&gt;I am new to dashboards building&lt;/P&gt;&lt;P&gt;Can I get the xml code pls&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 15:48:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684676#M19169</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2024-04-18T15:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: host drop down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684715#M19173</link>
      <description>&lt;P&gt;Can any one help on this&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 20:40:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684715#M19173</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2024-04-18T20:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: host drop down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684716#M19174</link>
      <description>&lt;P&gt;Can anyone help on this pls&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 20:41:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684716#M19174</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2024-04-18T20:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: host drop down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684732#M19181</link>
      <description>&lt;P&gt;I can help - I asked a question about whether you had already added the dropdown field.&lt;/P&gt;&lt;P&gt;Have you done so? What have you tried before - it's pretty straightforward to add a dropdown input and add values to the dashboard - you don't need to write XML&lt;/P&gt;&lt;P&gt;The XML reference manual is here&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This is a really good app you can install to a Splunk environment that shows many techniques to create powerful dashboards&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/1603" target="_blank"&gt;https://splunkbase.splunk.com/app/1603&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 00:35:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684732#M19181</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-04-19T00:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: host drop down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684733#M19182</link>
      <description>&lt;P&gt;Here is another page that pretty much shows you how to do this&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Viz/Buildandeditforms" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/Viz/Buildandeditforms&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 00:36:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/684733#M19182</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-04-19T00:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: host drop down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/685191#M19204</link>
      <description>&lt;P&gt;I tried below code but it not working. can any one let me know what is wrong here:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;form version="1.1" theme="light"&amp;gt;
&amp;lt;label&amp;gt;HTMD Dashboard&amp;lt;/label&amp;gt;
&amp;lt;fieldset submitButton="false"&amp;gt;
&amp;lt;input type="time" token="timepicker"&amp;gt;
&amp;lt;label&amp;gt;TimeRange&amp;lt;/label&amp;gt;
&amp;lt;default&amp;gt;
&amp;lt;earliest&amp;gt;-15m@m&amp;lt;/earliest&amp;gt;
&amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
&amp;lt;/default&amp;gt;
&amp;lt;/input&amp;gt;
&amp;lt;input type="dropdown" token="host"&amp;gt;
&amp;lt;label&amp;gt;Env wise hosts&amp;lt;/label&amp;gt;
&amp;lt;choice value="appdev1host","logdev1host","cordev1host"&amp;gt;DEV1&amp;lt;/choice&amp;gt;
&amp;lt;choice value="appdev2host","logdev2host","cordev2host"&amp;gt;DEV2&amp;lt;/choice&amp;gt;
&amp;lt;choice value="appdev3host","logdev3host","cordev3host"&amp;gt;DEV3&amp;lt;/choice&amp;gt;
&amp;lt;choice value="appdev4host","logdev4host","cordev4host"&amp;gt;DEV4&amp;lt;/choice&amp;gt;
&amp;lt;choice value="appsit1host","logsit1host","corsit1host"&amp;gt;SIT1&amp;lt;/choice&amp;gt;
&amp;lt;choice value="appsit2host","logsit2host","corsit2host"&amp;gt;SIT2&amp;lt;/choice&amp;gt;
&amp;lt;choice value="appsit3host","logsit3host","corsit3host"&amp;gt;SIT3&amp;lt;/choice&amp;gt;
&amp;lt;choice value="appsit4host","logsit4host","corsit4host"&amp;gt;SIT4&amp;lt;/choice&amp;gt;
&amp;lt;/fieldset&amp;gt;
&amp;lt;row&amp;gt;
&amp;lt;panel&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;title&amp;gt;Incoming Count &amp;amp;amp; Total Count&amp;lt;/title&amp;gt;
&amp;lt;search&amp;gt;
&amp;lt;query&amp;gt;index=test-index source=application.logs $host$ "Incoming count" |stats count by "Incoming count"
|appendcols
index=test-index source=application.logs $host$ "Total count" |stats count by "Total count"
|table "Incoming count" "Total count"
&amp;lt;/query&amp;gt;
&amp;lt;earliest&amp;gt;timepicker.earliest&amp;lt;/earliest&amp;gt;
&amp;lt;latest&amp;gt;timepicker.latest&amp;lt;/latest&amp;gt;
&amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
&amp;lt;/search&amp;gt;
&amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
&amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
&amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
&amp;lt;option name="percentageRow"&amp;gt;false&amp;lt;/option&amp;gt;
&amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
&amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
&amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
&amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;/panel&amp;gt;
&amp;lt;/row&amp;gt;
&amp;lt;form&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 23 Apr 2024 17:50:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/685191#M19204</guid>
      <dc:creator>Ash1</dc:creator>
      <dc:date>2024-04-23T17:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: host drop down</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/685228#M19211</link>
      <description>&lt;P&gt;I am not sure how you managed to create that because that XML is completely broken and is not a valid dashboard. Your &amp;lt;choice&amp;gt; values are not valid XML, e.g. you can't have value=multiple quoted strings.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;choice value="appdev1host","logdev1host","cordev1host"&amp;gt;DEV1&amp;lt;/choice&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;Why don't you just make your choice value something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;choice value="*dev1host"&amp;gt;DEV1&amp;lt;/choice&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;and so on.&lt;/P&gt;&lt;P&gt;Also, not sure what you are trying to achieve with your SPL - are "Total count" and "Incoming count" fields in your data? Using appendcols is not a good technique as you are repeating almost the identical search, which is not necessary.&lt;/P&gt;&lt;P&gt;If you want to share an example of your data I can help suggest a correct search.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 01:46:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/host-drop-down/m-p/685228#M19211</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-04-24T01:46:51Z</dc:date>
    </item>
  </channel>
</rss>

