<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tokens not propagating values in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Tokens-not-propagating-values/m-p/484908#M31798</link>
    <description>&lt;P&gt;This works at last.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jan 2020 08:04:26 GMT</pubDate>
    <dc:creator>riqbal47010</dc:creator>
    <dc:date>2020-01-20T08:04:26Z</dc:date>
    <item>
      <title>Tokens not propagating values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Tokens-not-propagating-values/m-p/484904#M31794</link>
      <description>&lt;P&gt;I have multiple Input text  boxes with comma separated input text values.&lt;/P&gt;

&lt;P&gt;below is my requirement.&lt;/P&gt;

&lt;P&gt;Box1 have domain names e.g. (&lt;A href="http://www.abc.com"&gt;www.abc.com&lt;/A&gt;, &lt;A href="http://www.xyz.com"&gt;www.xyz.com&lt;/A&gt;)&lt;BR /&gt;
Box2 have multiple MD5 hashes ( 'sdfsdfsdfsdf6546545645646','6564654654564654654564sd')&lt;BR /&gt;
Now I want that If i put comma seperated input to Box1 test box, it should open a search panel and show me the results.&lt;BR /&gt;
and If copy MD5 comma seperated hashes to Box2 text box, then the  panel1 should show me the results from Box2.&lt;BR /&gt;
and IF THERE IS NO INPUT AT ALL IN BOTH INPUTS BOXES THEN THE SEARCH PANEL ALSO SHOULD DISAPPEAR AND NO SEARCH SHOULD RUN IN BACKGROUND&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;Threat_Intelligance&amp;lt;/label&amp;gt;
  &amp;lt;description&amp;gt;Include a multiselect input.&amp;lt;/description&amp;gt;
  &amp;lt;!-- Independent search to set the required filter from comma separated value in text box --&amp;gt;
  &amp;lt;!-- For example: &lt;A href="https://community.splunk.com/www.abc.com,www.xyz.com,www.aaa.com" target="test_blank"&gt;www.abc.com,www.xyz.com,www.aaa.com&lt;/A&gt; converts to src_ip IN ("www.abc.com","www.xyz.com","www.aaa.com") --&amp;gt;
  &amp;lt;search&amp;gt;
    &amp;lt;query&amp;gt;| makeresults
   | fields - _time
   | eval iocFilter=$ioc1|s$
   | eval md5Filter=$md5|s$
   | eval iocFilter="url IN (\"".replace(iocFilter,",","\",\"")."\")"
   | eval md5Filter="process_md5 IN (\"".replace(md5Filter,",","\",\"")."\")"
       &amp;lt;/query&amp;gt;
    &amp;lt;done&amp;gt;
      &amp;lt;set token="tokIOCFilter"&amp;gt;$result.iocFilter$&amp;lt;/set&amp;gt;
      &amp;lt;set token="tokmd5Filter"&amp;gt;$result.md5Filter$&amp;lt;/set&amp;gt;
    &amp;lt;/done&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;fieldset autoRun="true" submitButton="true"&amp;gt;
    &amp;lt;input type="text" token="ioc1" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;URL&amp;lt;/label&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;condition&amp;gt;
          &amp;lt;set token="tokIOCFilter"&amp;gt;$result.iocFilter$&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
      &amp;lt;/change&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="text" token="md5"&amp;gt;
      &amp;lt;label&amp;gt;md5&amp;lt;/label&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;condition&amp;gt;
          &amp;lt;set token="tokmd5Filter"&amp;gt;$result.md5Filter$&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
      &amp;lt;/change&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="time" token="field1"&amp;gt;
      &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;event&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=proxy OR index=edr ($tokIOCFilter$  OR $tokmd5Filter$)&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/event&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 19 Jan 2020 13:42:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Tokens-not-propagating-values/m-p/484904#M31794</guid>
      <dc:creator>riqbal47010</dc:creator>
      <dc:date>2020-01-19T13:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Tokens not propagating values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Tokens-not-propagating-values/m-p/484905#M31795</link>
      <description>&lt;P&gt;@riqbal47010 Can you try the following steps one by one&lt;BR /&gt;
1. Add &lt;CODE&gt;searchWhenChanged="true"&lt;/CODE&gt; to md5 text box.&lt;BR /&gt;
2. Remove Submit Button i.e. &lt;CODE&gt;submitButton="false"&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;If the token behavior is still not as expected please let us know which scenario does not work (expected behavior vs actual behavior).&lt;/P&gt;

&lt;P&gt;Also refer to one of my older answers to understand Default and Submitted token models in Splunk: &lt;A href="https://answers.splunk.com/answers/742451/searchwhenchangedfalse-not-honored-1.html"&gt;https://answers.splunk.com/answers/742451/searchwhenchangedfalse-not-honored-1.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2020 14:50:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Tokens-not-propagating-values/m-p/484905#M31795</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2020-01-19T14:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Tokens not propagating values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Tokens-not-propagating-values/m-p/484906#M31796</link>
      <description>&lt;P&gt;You are doing waaaaaaaaaaaaaay too much work.  First of all, I think your modification from &lt;CODE&gt;OR&lt;/CODE&gt; to &lt;CODE&gt;IN&lt;/CODE&gt; is silly, and that was the beginning of all of your problems.  But presuming that you have some need for this, I have made that work (again, without that, your dashboard would have been brain-dead simple and worked the on the first try):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;Threat_Intelligance&amp;lt;/label&amp;gt;
  &amp;lt;description&amp;gt;Include a multiselect input.&amp;lt;/description&amp;gt;
   &amp;lt;fieldset autoRun="true" submitButton="true"&amp;gt;
    &amp;lt;input type="text" token="ioc1"&amp;gt;
      &amp;lt;label&amp;gt;URL&amp;lt;/label&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;condition match="len($value$)==0"&amp;gt;
          &amp;lt;unset token="ioc1"&amp;gt;&amp;lt;/unset&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition&amp;gt;
          &amp;lt;eval token="ioc1"&amp;gt;&amp;amp;quot;url IN (\&amp;amp;quot;&amp;amp;quot; . replace($value$, &amp;amp;quot;,&amp;amp;quot;, &amp;amp;quot;\&amp;amp;quot;, \&amp;amp;quot;&amp;amp;quot;) . &amp;amp;quot;\&amp;amp;quot;)&amp;amp;quot;&amp;lt;/eval&amp;gt;
        &amp;lt;/condition&amp;gt;
      &amp;lt;/change&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="text" token="md5"&amp;gt;
      &amp;lt;label&amp;gt;md5&amp;lt;/label&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;condition match="len($value$)==0"&amp;gt;
          &amp;lt;unset token="md5"&amp;gt;&amp;lt;/unset&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition&amp;gt;
          &amp;lt;eval token="md5"&amp;gt;&amp;amp;quot;process_md5 IN (\&amp;amp;quot;&amp;amp;quot; . replace($value$, &amp;amp;quot;,&amp;amp;quot;, &amp;amp;quot;\&amp;amp;quot;, \&amp;amp;quot;&amp;amp;quot;) . &amp;amp;quot;\&amp;amp;quot;)&amp;amp;quot;&amp;lt;/eval&amp;gt;
        &amp;lt;/condition&amp;gt;
      &amp;lt;/change&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="time" token="field1"&amp;gt;
      &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row depends="$ioc1$ $md5$"&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;ioc1="$ioc1$", md5="$md5$"&amp;lt;/title&amp;gt;
      &amp;lt;event&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=proxy OR index=edr ($ioc1$  OR $md5$)&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/event&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Personally, I would ditch the &lt;CODE&gt;Submit&lt;/CODE&gt; button and set everything else to &lt;CODE&gt;searchWhenChanged=true&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2020 19:51:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Tokens-not-propagating-values/m-p/484906#M31796</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-01-19T19:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Tokens not propagating values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Tokens-not-propagating-values/m-p/484907#M31797</link>
      <description>&lt;P&gt;hi wood,&lt;/P&gt;

&lt;P&gt;that's an interesting approach, &lt;BR /&gt;
I found that when I give input in bot text boxes then results appear, whereas I need one input at one time.&lt;BR /&gt;
i believe  below parameters are causing this.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   &amp;lt;row depends="$ioc1$ $md5$"&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;HOW CAN WE FIX THIS.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 07:23:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Tokens-not-propagating-values/m-p/484907#M31797</guid>
      <dc:creator>riqbal47010</dc:creator>
      <dc:date>2020-01-20T07:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Tokens not propagating values</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Tokens-not-propagating-values/m-p/484908#M31798</link>
      <description>&lt;P&gt;This works at last.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 08:04:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Tokens-not-propagating-values/m-p/484908#M31798</guid>
      <dc:creator>riqbal47010</dc:creator>
      <dc:date>2020-01-20T08:04:26Z</dc:date>
    </item>
  </channel>
</rss>

