<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic input value for tables in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465302#M30548</link>
    <description>&lt;P&gt;yes you can do.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2019 13:01:40 GMT</pubDate>
    <dc:creator>vnravikumar</dc:creator>
    <dc:date>2019-12-12T13:01:40Z</dc:date>
    <item>
      <title>Dynamic input value for tables</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465294#M30540</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I currently have a table showing all used commands from a specific machine. Search is something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="/var/log/log"  | stats count by comm | table comm, count | sort by count desc | head 10
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This shows the top 10 used commands. Now I would like to search for specific commands using an Input field and submit button.&lt;BR /&gt;
I would imagine the search would be something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="/var/log/audit/audit.log" comm="*$Token_Name$*" | stats count by comm | table comm, count | sort by count desc | head 10
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But I don't understand how I can use the input field to alter the existing table.. How should the input field be configured and how do I make the existing table use the input? Or does the input field create a table with given value?&lt;/P&gt;

&lt;P&gt;I hope my question is clear.. &lt;BR /&gt;
Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 12:27:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465294#M30540</guid>
      <dc:creator>jonydupre</dc:creator>
      <dc:date>2019-12-12T12:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic input value for tables</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465295#M30541</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Try like&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;textfield&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;
    &amp;lt;input type="text" token="field1"&amp;gt;
      &amp;lt;label&amp;gt;field1&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
      &amp;lt;prefix&amp;gt;sourcetype="&amp;lt;/prefix&amp;gt;
      &amp;lt;suffix&amp;gt;"&amp;lt;/suffix&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index="_internal" $field1$ | stats count by sourcetype&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 12 Dec 2019 12:33:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465295#M30541</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-12-12T12:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic input value for tables</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465296#M30542</link>
      <description>&lt;P&gt;Thanks, should I replace the text in &lt;CODE&gt;&amp;lt;query&amp;gt; &amp;lt;/query&amp;gt;&lt;/CODE&gt;  with my second query in the opening post?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 12:42:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465296#M30542</guid>
      <dc:creator>jonydupre</dc:creator>
      <dc:date>2019-12-12T12:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic input value for tables</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465297#M30543</link>
      <description>&lt;P&gt;yes, &lt;CODE&gt;$field1$&lt;/CODE&gt; is similar to your  &lt;CODE&gt;comm&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 12:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465297#M30543</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-12-12T12:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic input value for tables</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465298#M30544</link>
      <description>&lt;P&gt;So in my situation like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;input type="text" token="field1"&amp;gt;
      &amp;lt;label&amp;gt;field1&amp;lt;/label&amp;gt;
       &amp;lt;default&amp;gt;&amp;lt;/default&amp;gt;
       &amp;lt;prefix&amp;gt;sourcetype="&amp;lt;/prefix&amp;gt;
       &amp;lt;suffix&amp;gt;"&amp;lt;/suffix&amp;gt;
       &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Gebruikte commando's&amp;lt;/title&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;source="/var/log/log" comm="$field1$" | stats count by comm | table comm, count | sort by count desc | head 10&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Can you explain the prefix, suffix en initialValue? What are their functions?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 12:49:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465298#M30544</guid>
      <dc:creator>jonydupre</dc:creator>
      <dc:date>2019-12-12T12:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic input value for tables</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465299#M30545</link>
      <description>&lt;P&gt;hi&lt;/P&gt;

&lt;P&gt;Check this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;fieldset&amp;gt;
    &amp;lt;input type="text" token="field1"&amp;gt;
      &amp;lt;label&amp;gt;field1&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;&amp;lt;/default&amp;gt;
      &amp;lt;prefix&amp;gt;comm="&amp;lt;/prefix&amp;gt;
      &amp;lt;suffix&amp;gt;"&amp;lt;/suffix&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Gebruikte commando's&amp;lt;/title&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;source="/var/log/log" $field1$ | stats count by comm | table comm, count | sort by count desc | head 10&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 12 Dec 2019 12:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465299#M30545</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-12-12T12:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic input value for tables</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465300#M30546</link>
      <description>&lt;P&gt;instead of giving in query like &lt;CODE&gt;comm=$field1$&lt;/CODE&gt; i'm building that in token itself&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 12:53:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465300#M30546</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-12-12T12:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic input value for tables</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465301#M30547</link>
      <description>&lt;P&gt;Thanks, but why use prefix/suffix? I could just put $field1$ in the search after comm=" right?&lt;/P&gt;

&lt;P&gt;Like this: &lt;BR /&gt;
source="/var/log/log" comm="&lt;EM&gt;$field1$&lt;/EM&gt;" | stats count by comm | table comm, count | sort by count desc | head 10&lt;/P&gt;

&lt;P&gt;And not use prefix/suffix in the input field, or is this not possible?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 13:00:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465301#M30547</guid>
      <dc:creator>jonydupre</dc:creator>
      <dc:date>2019-12-12T13:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic input value for tables</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465302#M30548</link>
      <description>&lt;P&gt;yes you can do.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 13:01:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465302#M30548</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-12-12T13:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic input value for tables</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465303#M30549</link>
      <description>&lt;P&gt;Ok thanks, it works now. But why would you use the suffix/preffix? Or is it a habit to use like that?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 14:33:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Dynamic-input-value-for-tables/m-p/465303#M30549</guid>
      <dc:creator>jonydupre</dc:creator>
      <dc:date>2019-12-12T14:33:44Z</dc:date>
    </item>
  </channel>
</rss>

