<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using mvmap in eval token in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Using-mvmap-in-eval-token/m-p/581436#M47644</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49493"&gt;@tscroggins&lt;/a&gt;, thank you for the detailed explanation, and also for pointing out where I should look for the answer the next time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jan 2022 10:20:06 GMT</pubDate>
    <dc:creator>piukr</dc:creator>
    <dc:date>2022-01-18T10:20:06Z</dc:date>
    <item>
      <title>Using mvmap in eval token</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Using-mvmap-in-eval-token/m-p/580940#M47605</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to format multi-value cell data in a dashboard table using mvmap in an eval token before passing it on to a drilldown, however I am unable to figure out how to format the eval function and if this approach would work at all. I would appreciate if someone could tell me why this function fails.&lt;/P&gt;&lt;P&gt;I have included a test dashboard which shows sample data (sample column) and the format that I would like to create (test column). Unfortunately, the 'temptoken' token never gets evaluated.&lt;/P&gt;&lt;P&gt;Note, I understand that I could use different workarounds to avoid using mvmap in an eval token, such as creating a hidden field in the table and use it for drilldown, or using different eval functions (depending on the use case). I am specifically interested in the format of using mvmap in an eval token, as this function could be really useful in more complex cases that I have to deal with.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;mvmap in eval token&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;
            &amp;lt;![CDATA[
| makeresults 
| fields - _time
| eval sample = "text1 -&amp;gt; text2,text3 -&amp;gt; text4"
| eval sample = split(sample, ",")
``` the SPL above this line will generate the sample data ```
| eval test = mvmap(sample, split(sample, " -&amp;gt; "))
          ]]&amp;gt;
        &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;drilldown&amp;gt;
          &amp;lt;condition match="$click.name2$==&amp;amp;quot;sample&amp;amp;quot;"&amp;gt;
           &amp;lt;!-- This eval function is not working --&amp;gt; 
           &amp;lt;eval token="temptoken"&amp;gt;mvmap('row.sample', split('row.sample', " -&amp;gt; "))&amp;lt;/eval&amp;gt;
          &amp;lt;/condition&amp;gt;
          &amp;lt;condition match="$click.name2$==&amp;amp;quot;test&amp;amp;quot;"&amp;gt;
            &amp;lt;eval token="temptoken2"&amp;gt;'row.test'&amp;lt;/eval&amp;gt;
          &amp;lt;/condition&amp;gt;
        &amp;lt;/drilldown&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;html&amp;gt;
      &amp;lt;p&amp;gt;
        temptoken: $temptoken$
      &amp;lt;/p&amp;gt;
      &amp;lt;p&amp;gt;
        temptoken2: $temptoken2$
      &amp;lt;/p&amp;gt;
    &amp;lt;/html&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 13:00:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Using-mvmap-in-eval-token/m-p/580940#M47605</guid>
      <dc:creator>piukr</dc:creator>
      <dc:date>2022-01-13T13:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: Using mvmap in eval token</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Using-mvmap-in-eval-token/m-p/581274#M47625</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238266"&gt;@piukr&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Simple XML &amp;lt;eval&amp;gt; tag implements a subset of eval functions in JavaScript. Internally, multivalued results are JavaScript arrays. They are collapsed to comma-delimited strings when returned as values.&lt;/P&gt;&lt;P&gt;See $SPLUNK_HOME/share/splunk/search_mrsparkle/exposed/js/util/eval/functions/multivalue.js for the list of supported functions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;split()&lt;/LI&gt;&lt;LI&gt;mvappend()&lt;/LI&gt;&lt;LI&gt;mvcount()&lt;/LI&gt;&lt;LI&gt;mvfind()&lt;/LI&gt;&lt;LI&gt;mvindex()&lt;/LI&gt;&lt;LI&gt;mvjoin()&lt;/LI&gt;&lt;LI&gt;mvdedup()&lt;/LI&gt;&lt;LI&gt;mvsort()&lt;/LI&gt;&lt;LI&gt;mvrange()&lt;/LI&gt;&lt;LI&gt;mvzip()&lt;/LI&gt;&lt;LI&gt;mvfilter()&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Unfortunately, mvmap() is not supported.&lt;/P&gt;&lt;P&gt;Props to the dashboards and visualizations team for supporting as much as they did!&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 00:15:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Using-mvmap-in-eval-token/m-p/581274#M47625</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2022-01-17T00:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Using mvmap in eval token</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Using-mvmap-in-eval-token/m-p/581436#M47644</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49493"&gt;@tscroggins&lt;/a&gt;, thank you for the detailed explanation, and also for pointing out where I should look for the answer the next time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 10:20:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Using-mvmap-in-eval-token/m-p/581436#M47644</guid>
      <dc:creator>piukr</dc:creator>
      <dc:date>2022-01-18T10:20:06Z</dc:date>
    </item>
  </channel>
</rss>

