<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to filter events based on comma deilmeter? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293081#M18617</link>
    <description>&lt;P&gt;I have to filter the events by matching against the comma separated values. For example, &lt;BR /&gt;
I have an input text box field. If I type 123, 231, 356, I have to filter the events by matching against the comma separated fields.&lt;/P&gt;

&lt;P&gt;It should be ('123' OR '231' OR '356'). I have tried assigning the exact string to the &lt;CODE&gt;searchmatch()&lt;/CODE&gt; function. But seems like it ANDing the values instead of OR. Following is my query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;Filter Dashboard&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false" autoRun="true"&amp;gt;    
    &amp;lt;input type="text" token="filter_tok" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;Filter&amp;lt;/label&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;My Panel&amp;lt;/title&amp;gt;
      &amp;lt;event&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=* | where searchmatch("$filter_tok$") &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-30m@m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;         
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;5&amp;lt;/option&amp;gt;
        &amp;lt;option name="list.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
        &amp;lt;option name="list.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="maxLines"&amp;gt;5&amp;lt;/option&amp;gt;
        &amp;lt;option name="raw.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="table.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
        &amp;lt;option name="table.sortDirection"&amp;gt;asc&amp;lt;/option&amp;gt;
        &amp;lt;option name="table.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="type"&amp;gt;list&amp;lt;/option&amp;gt;
      &amp;lt;/event&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How to achieve this? Please suggest.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Nov 2017 10:19:14 GMT</pubDate>
    <dc:creator>Naren26</dc:creator>
    <dc:date>2017-11-22T10:19:14Z</dc:date>
    <item>
      <title>How to filter events based on comma deilmeter?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293081#M18617</link>
      <description>&lt;P&gt;I have to filter the events by matching against the comma separated values. For example, &lt;BR /&gt;
I have an input text box field. If I type 123, 231, 356, I have to filter the events by matching against the comma separated fields.&lt;/P&gt;

&lt;P&gt;It should be ('123' OR '231' OR '356'). I have tried assigning the exact string to the &lt;CODE&gt;searchmatch()&lt;/CODE&gt; function. But seems like it ANDing the values instead of OR. Following is my query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;Filter Dashboard&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false" autoRun="true"&amp;gt;    
    &amp;lt;input type="text" token="filter_tok" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;Filter&amp;lt;/label&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;My Panel&amp;lt;/title&amp;gt;
      &amp;lt;event&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=* | where searchmatch("$filter_tok$") &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-30m@m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;         
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;5&amp;lt;/option&amp;gt;
        &amp;lt;option name="list.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
        &amp;lt;option name="list.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="maxLines"&amp;gt;5&amp;lt;/option&amp;gt;
        &amp;lt;option name="raw.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="table.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
        &amp;lt;option name="table.sortDirection"&amp;gt;asc&amp;lt;/option&amp;gt;
        &amp;lt;option name="table.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="type"&amp;gt;list&amp;lt;/option&amp;gt;
      &amp;lt;/event&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How to achieve this? Please suggest.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 10:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293081#M18617</guid>
      <dc:creator>Naren26</dc:creator>
      <dc:date>2017-11-22T10:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter events based on comma deilmeter?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293082#M18618</link>
      <description>&lt;P&gt;Try with IN clause. &lt;/P&gt;

&lt;P&gt;i.e Following query only prints events from two hosts as mentioned in the IN clause.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=main  host IN ("CDSLMAC02.local","127.0.0.1") 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 22 Nov 2017 10:34:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293082#M18618</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2017-11-22T10:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter events based on comma deilmeter?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293083#M18619</link>
      <description>&lt;P&gt;@hardikJsheth I need to perform a random search. Not specified to any field&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 10:40:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293083#M18619</guid>
      <dc:creator>Naren26</dc:creator>
      <dc:date>2017-11-22T10:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter events based on comma deilmeter?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293084#M18620</link>
      <description>&lt;P&gt;HI&lt;/P&gt;

&lt;P&gt;Can you please try this?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
   &amp;lt;label&amp;gt;Filter Dashboard&amp;lt;/label&amp;gt;
   &amp;lt;fieldset submitButton="false" autoRun="true"&amp;gt;    
     &amp;lt;input type="text" token="filter_tok" searchWhenChanged="true"&amp;gt;
       &amp;lt;label&amp;gt;Filter&amp;lt;/label&amp;gt;
       &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
       &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
     &amp;lt;/input&amp;gt;
   &amp;lt;/fieldset&amp;gt;
   &amp;lt;search&amp;gt;
           &amp;lt;query&amp;gt;| makeresults | eval value="$filter_tok$" | makemv delim="," value | mvexpand value | stats delim=" OR " values(value) as value | mvcombine value &amp;lt;/query&amp;gt;
           &amp;lt;done&amp;gt;
             &amp;lt;set token="myToken"&amp;gt;$result.value$&amp;lt;/set&amp;gt;
           &amp;lt;/done&amp;gt;
   &amp;lt;/search&amp;gt;
   &amp;lt;row&amp;gt;
     &amp;lt;panel&amp;gt;
       &amp;lt;title&amp;gt;My Panel $myToken$&amp;lt;/title&amp;gt;
       &amp;lt;event&amp;gt;
         &amp;lt;search&amp;gt;
           &amp;lt;query&amp;gt;index=* | where searchmatch("$myToken$") &amp;lt;/query&amp;gt;
           &amp;lt;earliest&amp;gt;-30m@m&amp;lt;/earliest&amp;gt;
           &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;         
           &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
         &amp;lt;/search&amp;gt;
         &amp;lt;option name="count"&amp;gt;5&amp;lt;/option&amp;gt;
         &amp;lt;option name="list.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
         &amp;lt;option name="list.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
         &amp;lt;option name="maxLines"&amp;gt;5&amp;lt;/option&amp;gt;
         &amp;lt;option name="raw.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
         &amp;lt;option name="rowNumbers"&amp;gt;0&amp;lt;/option&amp;gt;
         &amp;lt;option name="table.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
         &amp;lt;option name="table.sortDirection"&amp;gt;asc&amp;lt;/option&amp;gt;
         &amp;lt;option name="table.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
         &amp;lt;option name="type"&amp;gt;list&amp;lt;/option&amp;gt;
       &amp;lt;/event&amp;gt;
     &amp;lt;/panel&amp;gt;
   &amp;lt;/row&amp;gt;
 &amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 10:48:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293084#M18620</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2017-11-22T10:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter events based on comma deilmeter?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293085#M18621</link>
      <description>&lt;P&gt;Excellent. Worked perfectly fine. Thanks a lot @kamlesh_vaghela&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 11:10:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293085#M18621</guid>
      <dc:creator>Naren26</dc:creator>
      <dc:date>2017-11-22T11:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter events based on comma deilmeter?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293086#M18622</link>
      <description>&lt;P&gt;@Naren26,  I got it.&lt;/P&gt;

&lt;P&gt;The best solution would be to replace coma with OR from token in  java script .&lt;/P&gt;

&lt;P&gt;i.e index=main  "CDSLMAC02.local" OR "127.0.0.1"  &lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 11:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-filter-events-based-on-comma-deilmeter/m-p/293086#M18622</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2017-11-22T11:36:16Z</dc:date>
    </item>
  </channel>
</rss>

