<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help for linking my request with a token in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385845#M95769</link>
    <description>&lt;P&gt;thanks it works&lt;/P&gt;</description>
    <pubDate>Mon, 07 Jan 2019 07:18:16 GMT</pubDate>
    <dc:creator>jip31</dc:creator>
    <dc:date>2019-01-07T07:18:16Z</dc:date>
    <item>
      <title>help for linking my request with a token</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385840#M95764</link>
      <description>&lt;P&gt;hi&lt;BR /&gt;
i use the request below and I want to link it with a token&lt;BR /&gt;
my token is called "tok_filterhost" and I add host=$tok_filterhost$" in my query in order to have a result if the host is good and no result if the host is bad&lt;BR /&gt;
but I have no results&lt;BR /&gt;
could you help me please??&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;eventtype="DiskHealthSize" 
| dedup host 
| eval time = strftime(_time, "%m/%d/%Y %H:%M") 
| eval Value = round(Value, 1) 
| eval TotalSpace = TotalSpaceKB/1024 
| eval TotalSpace = round(TotalSpace/1024,1). " MB" 
| rename Value as Free_Space 
| eval Free_Space= if(Free_Space&amp;gt;15, "GOOD", "BAD") 
| table Free_Space
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:34:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385840#M95764</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2020-09-29T22:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: help for linking my request with a token</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385841#M95765</link>
      <description>&lt;P&gt;@jip31, where did you add the token? Do you mind sharing the xml part where the token is assigned and added?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 13:02:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385841#M95765</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2019-01-04T13:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: help for linking my request with a token</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385842#M95766</link>
      <description>&lt;P&gt;yes but it doesnt works&lt;/P&gt;

&lt;P&gt;here is the xml&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;Hard Disk&amp;lt;/label&amp;gt;
  &amp;lt;description&amp;gt;Disk health checking - Slot time : 30 days&amp;lt;/description&amp;gt;
  &amp;lt;fieldset submitButton="true"&amp;gt;
    &amp;lt;input type="text" searchWhenChanged="true" token="tok_filterhost"&amp;gt;
      &amp;lt;label&amp;gt;HostName&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Disk Remaining Space Status&amp;lt;/title&amp;gt;
      &amp;lt;html depends="$alwaysHideCSSStylePanel$"&amp;gt;
       &amp;lt;style&amp;gt;
          #singleWithCSSOverride1 svg.svg-container rect{
             fill: $tokColor1$ !important;
           #singleWithCSSOverride2 svg.svg-container rect{
             fill: $tokColor2$ !important;
           }
        &amp;lt;/style&amp;gt;
       &amp;lt;/html&amp;gt;
      &amp;lt;single id="singleWithCSSOverride1"&amp;gt;
        &amp;lt;title&amp;gt;Good : &amp;amp;gt; 15% - Bad : &amp;amp;lt; 15%&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| loadjob savedsearch="admin:FO_Workstations_Monitoring:FO_Workstations_Disk_Size"&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="colorMode"&amp;gt;block&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Disk Health Status&amp;lt;/title&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;title&amp;gt;Good : Status = OK - Bad : Status = Not OK&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| loadjob savedsearch="admin:FO_Workstations_Monitoring:FO_Workstations_Disk_Status"&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="colorBy"&amp;gt;value&amp;lt;/option&amp;gt;
        &amp;lt;option name="colorMode"&amp;gt;block&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeColors"&amp;gt;["0x555","0x555"]&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeValues"&amp;gt;[0]&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Disk Remaining Space Status Details&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| loadjob savedsearch="admin:FO_Workstations_Monitoring:FO_Workstations_Disk_Size_Details" 
| search host=$tok_filterhost$&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Disk Health Status Details&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| loadjob savedsearch="admin:FO_Workstations_Monitoring:FO_Workstations_Disk_Status_Details" 
| search host=$tok_filterhost$&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;format type="color" field="Status"&amp;gt;
          &amp;lt;colorPalette type="map"&amp;gt;{"OK":#3863A0}&amp;lt;/colorPalette&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 04 Jan 2019 14:26:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385842#M95766</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2019-01-04T14:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: help for linking my request with a token</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385843#M95767</link>
      <description>&lt;P&gt;What are the fields in the result of &lt;CODE&gt;savedsearch="admin:FO_Workstations_Monitoring:FO_Workstations_Disk_Status_Details"&lt;/CODE&gt;. Does it have &lt;CODE&gt;host&lt;/CODE&gt; field?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 15:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385843#M95767</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2019-01-04T15:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: help for linking my request with a token</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385844#M95768</link>
      <description>&lt;P&gt;@jip31 the query you have posted in your question performs &lt;CODE&gt;| table Free_Space&lt;/CODE&gt; command in the end. Which implies it drops the host field which is possibly why your search filter with &lt;CODE&gt;| where host="$tok_filterhost$"&lt;/CODE&gt; is not working.&lt;/P&gt;

&lt;P&gt;Since you are using &lt;CODE&gt;loadjob&lt;/CODE&gt; to return the results of saved search &lt;CODE&gt;"admin:FO_Workstations_Monitoring:FO_Workstations_Disk_Status_Details"&lt;/CODE&gt;, either you need to change the saved search to add &lt;CODE&gt;host&lt;/CODE&gt; to final output or created a new saved search with both host and Free_Space returned as result. In any case saved search final pipe should be the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | table host Free_Space
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In your actual dashboard you can &lt;CODE&gt;post-processing&lt;/CODE&gt; to show only FreeSpace without host name.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jan 2019 04:23:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385844#M95768</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2019-01-05T04:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: help for linking my request with a token</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385845#M95769</link>
      <description>&lt;P&gt;thanks it works&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 07:18:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-for-linking-my-request-with-a-token/m-p/385845#M95769</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2019-01-07T07:18:16Z</dc:date>
    </item>
  </channel>
</rss>

