<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Autosuggest in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447319#M41177</link>
    <description>&lt;P&gt;Other searches in my environment run fine. I think it freezes because there are millions of servers in the database and splunk has difficulty processing all of them into one multiselect input&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jul 2018 14:17:47 GMT</pubDate>
    <dc:creator>TylerJVitale</dc:creator>
    <dc:date>2018-07-19T14:17:47Z</dc:date>
    <item>
      <title>Autosuggest</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447313#M41171</link>
      <description>&lt;P&gt;I'm creating a dashboard with text inputs. Is there a way to get Splunk to have a dropdown with autosuggestions when the user types in the text box, similar to how it works in the Search and Reporting app?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 13:11:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447313#M41171</guid>
      <dc:creator>TylerJVitale</dc:creator>
      <dc:date>2018-07-18T13:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Autosuggest</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447314#M41172</link>
      <description>&lt;P&gt;@TylerJVitale,&lt;/P&gt;

&lt;P&gt;You could use &lt;CODE&gt;Multiselect&lt;/CODE&gt; input for that where you could load all your possible dataset and when user start typing, the results are popped up. In text box, there are no ways to pre-populate except the default data.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 16:34:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447314#M41172</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2018-07-18T16:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: Autosuggest</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447315#M41173</link>
      <description>&lt;P&gt;That seems like it would work. How would I set it up so I could load the dataset i.e. in the input settings what would I have to select/adjust?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 17:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447315#M41173</guid>
      <dc:creator>TylerJVitale</dc:creator>
      <dc:date>2018-07-18T17:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: Autosuggest</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447316#M41174</link>
      <description>&lt;P&gt;Please see a sample dashboard which could be run anywhere&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;Tyler J Vitale&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;
    &amp;lt;input type="multiselect" token="sourcetype" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;Sourcetype&amp;lt;/label&amp;gt;
      &amp;lt;valuePrefix&amp;gt;sourcetype="&amp;lt;/valuePrefix&amp;gt;
      &amp;lt;valueSuffix&amp;gt;"&amp;lt;/valueSuffix&amp;gt;
      &amp;lt;delimiter&amp;gt; OR &amp;lt;/delimiter&amp;gt;
      &amp;lt;fieldForLabel&amp;gt;sourcetype&amp;lt;/fieldForLabel&amp;gt;
      &amp;lt;fieldForValue&amp;gt;sourcetype&amp;lt;/fieldForValue&amp;gt;
      &amp;lt;search&amp;gt;
        &amp;lt;query&amp;gt;index=_*|stats count by sourcetype&amp;lt;/query&amp;gt;
        &amp;lt;earliest&amp;gt;-15m&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/search&amp;gt;
      &amp;lt;prefix&amp;gt;(&amp;lt;/prefix&amp;gt;
      &amp;lt;suffix&amp;gt;)&amp;lt;/suffix&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_* $sourcetype$ |timechart count by sourcetype&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-15m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="charting.chart"&amp;gt;line&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;zero&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.layout.splitSeries"&amp;gt;0&amp;lt;/option&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 19 Jul 2018 02:04:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447316#M41174</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2018-07-19T02:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Autosuggest</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447317#M41175</link>
      <description>&lt;P&gt;The dashboard keeps freezing every time I try to implement this&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 12:50:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447317#M41175</guid>
      <dc:creator>TylerJVitale</dc:creator>
      <dc:date>2018-07-19T12:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Autosuggest</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447318#M41176</link>
      <description>&lt;P&gt;Its quite strange, because we are selecting only last 15 mins data. This is a smoothly running dashboard on my mobile device. You need to select a sourcetype in the multiselect to run the dashboard. What about other searches in your environment?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 14:12:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447318#M41176</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2018-07-19T14:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Autosuggest</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447319#M41177</link>
      <description>&lt;P&gt;Other searches in my environment run fine. I think it freezes because there are millions of servers in the database and splunk has difficulty processing all of them into one multiselect input&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 14:17:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Autosuggest/m-p/447319#M41177</guid>
      <dc:creator>TylerJVitale</dc:creator>
      <dc:date>2018-07-19T14:17:47Z</dc:date>
    </item>
  </channel>
</rss>

