<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change search depending on dropdown in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426712#M42177</link>
    <description>&lt;P&gt;Use the code below to understand how to "tokenize" the &lt;CODE&gt;source&lt;/CODE&gt; field&lt;BR /&gt;
for your code, replace the search which generates the tokens with &lt;CODE&gt;index=osnixsec src=* | stats count by src | table src&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;Dropdown Source&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;
    &amp;lt;input type="dropdown" token="SRC"&amp;gt;
      &amp;lt;label&amp;gt;Chhose Source&amp;lt;/label&amp;gt;
      &amp;lt;fieldForLabel&amp;gt;source&amp;lt;/fieldForLabel&amp;gt;
      &amp;lt;fieldForValue&amp;gt;source&amp;lt;/fieldForValue&amp;gt;
      &amp;lt;search&amp;gt;
        &amp;lt;query&amp;gt;index= _internal source=* 
| stats count by source
| table source&amp;lt;/query&amp;gt;
        &amp;lt;earliest&amp;gt;-4h@m&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/search&amp;gt;
      &amp;lt;choice value="*"&amp;gt;ALL&amp;lt;/choice&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index = _internal source=$SRC$ | stats count by source&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-15m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;50&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;title&amp;gt;Over Time&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal source="$SRC$" | timechart count by source&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="charting.chart"&amp;gt;line&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
    <pubDate>Fri, 26 Apr 2019 02:14:28 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2019-04-26T02:14:28Z</dc:date>
    <item>
      <title>Change search depending on dropdown</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426711#M42176</link>
      <description>&lt;P&gt;Hi peeps,&lt;/P&gt;

&lt;P&gt;I'd like to add a dropdown to my dashboard panel, which populates with "src" for the user to select, then based on what "src" is selected, it changes the panels below it. How easy is this to achieve? I've attached my current XML, in case this helps anyone understand what i'd like to achieve!&lt;/P&gt;

&lt;P&gt;I've tried playing with the dropdown input in the UI, but i can't seem to get my head around what to put in what boxes!&lt;/P&gt;

&lt;P&gt;Many thanks,&lt;BR /&gt;
Chris&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form theme="dark"&amp;gt;
  &amp;lt;label&amp;gt;Humbert root Logins&amp;lt;/label&amp;gt;
  &amp;lt;description&amp;gt;Track Root logins on humbert.ex.ac.uk&amp;lt;/description&amp;gt;
  &amp;lt;fieldset submitButton="false" autoRun="true"&amp;gt;
    &amp;lt;input type="time" token="field1"&amp;gt;
      &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
&amp;lt;panel&amp;gt;
  &amp;lt;title&amp;gt;Root Logins&amp;lt;/title&amp;gt;
  &amp;lt;single&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=osnixsec src=humber.ex.ac.uk user=root AND action=failure 
| stats count&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;
      &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
      &amp;lt;refresh&amp;gt;5m&amp;lt;/refresh&amp;gt;
      &amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="colorBy"&amp;gt;value&amp;lt;/option&amp;gt;
    &amp;lt;option name="colorMode"&amp;gt;block&amp;lt;/option&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
    &amp;lt;option name="numberPrecision"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="rangeColors"&amp;gt;["0x53a051","0x006d9c","0xf8be34","0xdc4e41"]&amp;lt;/option&amp;gt;
    &amp;lt;option name="rangeValues"&amp;gt;[0,30,50]&amp;lt;/option&amp;gt;
    &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
    &amp;lt;option name="showSparkline"&amp;gt;1&amp;lt;/option&amp;gt;
    &amp;lt;option name="showTrendIndicator"&amp;gt;1&amp;lt;/option&amp;gt;
    &amp;lt;option name="trellis.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="trellis.scales.shared"&amp;gt;1&amp;lt;/option&amp;gt;
    &amp;lt;option name="trellis.size"&amp;gt;medium&amp;lt;/option&amp;gt;
    &amp;lt;option name="trendColorInterpretation"&amp;gt;standard&amp;lt;/option&amp;gt;
    &amp;lt;option name="trendDisplayMode"&amp;gt;absolute&amp;lt;/option&amp;gt;
    &amp;lt;option name="underLabel"&amp;gt;Number of attempted logins&amp;lt;/option&amp;gt;
    &amp;lt;option name="unitPosition"&amp;gt;after&amp;lt;/option&amp;gt;
    &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;
    &amp;lt;option name="useThousandSeparators"&amp;gt;1&amp;lt;/option&amp;gt;
  &amp;lt;/single&amp;gt;
&amp;lt;/panel&amp;gt;
&amp;lt;/row&amp;gt;
&amp;lt;row&amp;gt;
&amp;lt;panel&amp;gt;
  &amp;lt;title&amp;gt;Destination Root attempts from Humbert&amp;lt;/title&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=osnixsec src=humbert.ex.ac.uk user=root AND action=failure  
  | stats count by dest 
  | sort -count 
  | rename dest as "Destination Host"&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;
      &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
      &amp;lt;refresh&amp;gt;5m&amp;lt;/refresh&amp;gt;
      &amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
    &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 25 Apr 2019 15:11:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426711#M42176</guid>
      <dc:creator>chrispounds</dc:creator>
      <dc:date>2019-04-25T15:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Change search depending on dropdown</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426712#M42177</link>
      <description>&lt;P&gt;Use the code below to understand how to "tokenize" the &lt;CODE&gt;source&lt;/CODE&gt; field&lt;BR /&gt;
for your code, replace the search which generates the tokens with &lt;CODE&gt;index=osnixsec src=* | stats count by src | table src&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;Dropdown Source&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;
    &amp;lt;input type="dropdown" token="SRC"&amp;gt;
      &amp;lt;label&amp;gt;Chhose Source&amp;lt;/label&amp;gt;
      &amp;lt;fieldForLabel&amp;gt;source&amp;lt;/fieldForLabel&amp;gt;
      &amp;lt;fieldForValue&amp;gt;source&amp;lt;/fieldForValue&amp;gt;
      &amp;lt;search&amp;gt;
        &amp;lt;query&amp;gt;index= _internal source=* 
| stats count by source
| table source&amp;lt;/query&amp;gt;
        &amp;lt;earliest&amp;gt;-4h@m&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/search&amp;gt;
      &amp;lt;choice value="*"&amp;gt;ALL&amp;lt;/choice&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index = _internal source=$SRC$ | stats count by source&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-15m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;50&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;title&amp;gt;Over Time&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal source="$SRC$" | timechart count by source&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="charting.chart"&amp;gt;line&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 02:14:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426712#M42177</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-04-26T02:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Change search depending on dropdown</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426713#M42178</link>
      <description>&lt;P&gt;Hi adonio, &lt;/P&gt;

&lt;P&gt;Thank you - so i implemented that into a test dashboard and changed the query's to match mine. But when i select the dropdown, all i get is the ALL value, not a list of available "src" values, do i need to adjust the choice value tag also?&lt;/P&gt;

&lt;P&gt;Many thanks for your help!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 09:24:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426713#M42178</guid>
      <dc:creator>chrispounds</dc:creator>
      <dc:date>2019-04-26T09:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: Change search depending on dropdown</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426714#M42179</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;&amp;lt;label&amp;gt;Dropdown Source&amp;lt;/label&amp;gt;
   &amp;lt;fieldset submitButton="false"&amp;gt;
     &amp;lt;input type="dropdown" token="SRC"&amp;gt;
       &amp;lt;label&amp;gt;Chhose Source&amp;lt;/label&amp;gt;
       &amp;lt;fieldForLabel&amp;gt;src&amp;lt;/fieldForLabel&amp;gt;
       &amp;lt;fieldForValue&amp;gt;src&amp;lt;/fieldForValue&amp;gt;
       &amp;lt;search&amp;gt;
         &amp;lt;query&amp;gt;index= index=osnixsec src=* | stats count by src | table src&amp;lt;/query&amp;gt;
         &amp;lt;earliest&amp;gt;-4h@m&amp;lt;/earliest&amp;gt;
         &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
       &amp;lt;/search&amp;gt;
       &amp;lt;choice value="*"&amp;gt;ALL&amp;lt;/choice&amp;gt;
       &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
       &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
     &amp;lt;/input&amp;gt;
   &amp;lt;/fieldset&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 26 Apr 2019 11:48:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426714#M42179</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-04-26T11:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Change search depending on dropdown</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426715#M42180</link>
      <description>&lt;P&gt;thanks adonio for your assistance, this doesn't actually give me a list in the dropdown. All it contains is "ALL" in capitals and doesn't list available src's to select. The queries run ok, but the dropdown isn't populating with the results from "src"&lt;/P&gt;

&lt;P&gt;Many thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 12:41:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426715#M42180</guid>
      <dc:creator>chrispounds</dc:creator>
      <dc:date>2019-04-26T12:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: Change search depending on dropdown</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426716#M42181</link>
      <description>&lt;P&gt;i see the problem&lt;BR /&gt;
look at the query i put - it has &lt;CODE&gt;index= index=osnixsec src=*&lt;/CODE&gt;&lt;BR /&gt;
itll break your search&lt;BR /&gt;
remove the first &lt;CODE&gt;index=&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;so you will only have: &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&amp;lt;query&amp;gt;index=osnixsec src=* | stats count by src | table src&amp;lt;/query&amp;gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 12:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426716#M42181</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-04-26T12:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Change search depending on dropdown</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426717#M42182</link>
      <description>&lt;P&gt;Yes that got it! fantastic adonio thank you! I should of proof read it also, lesson learnt! &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 12:53:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-depending-on-dropdown/m-p/426717#M42182</guid>
      <dc:creator>chrispounds</dc:creator>
      <dc:date>2019-04-26T12:53:45Z</dc:date>
    </item>
  </channel>
</rss>

