<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to limit instance according to drop down value selected for date filter in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657592#M54176</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please guide me on this .&lt;/P&gt;</description>
    <pubDate>Thu, 14 Sep 2023 12:10:31 GMT</pubDate>
    <dc:creator>aditsss</dc:creator>
    <dc:date>2023-09-14T12:10:31Z</dc:date>
    <item>
      <title>How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657560#M54169</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I have below query:&lt;/P&gt;&lt;P&gt;index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"&lt;BR /&gt;| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")&lt;BR /&gt;| eval EBNCStatus="ebnc event balanced successfully"|dedup&amp;nbsp;EBNCStatus&lt;BR /&gt;| table EBNCStatus True&lt;/P&gt;&lt;P&gt;I am deduping my EBNC status so when I am selecting date Filter as yesterday its showing one count but when I am selecting 7 days from date filter still showing one count.&lt;/P&gt;&lt;P&gt;I want when I select 7 its should show 7 count .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone help me with this,&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 08:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657560#M54169</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-14T08:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657563#M54170</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry, but if you use a fixed (for all events) value for&amp;nbsp;&lt;SPAN&gt;EBNCStatus, you'll have always only one value in this field, so when you'll dedup for this field, you'll always have one value!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could you better describe your requirement?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 09:07:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657563#M54170</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-14T09:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657571#M54173</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently when I am doing&amp;nbsp; dedup and selecting last 7 days its showing only event.&lt;/P&gt;&lt;P&gt;I want when I select last 7 days it should show 7 times that message.&lt;/P&gt;&lt;P&gt;when I select last 30 days it should 30 times that message.&lt;/P&gt;&lt;P&gt;Can you help me with this.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 10:07:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657571#M54173</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-14T10:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657572#M54174</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said,&amp;nbsp;&lt;SPAN&gt;if you use a fixed (for all events) value for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;EBNCStatus, you'll have always only one value in this field, so when you'll dedup for this field, you'll always have one value!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;try to delete the dedup row and see what&amp;nbsp; happens.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You could try to dedup for the&amp;nbsp;EBNCStatus field and another field (e.g. day), something like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"
| eval 
   True=if(searchmatch("ebnc event balanced successfully"),"✔",""),
   EBNCStatus="ebnc event balanced successfully",
   Day=strftime(_time,"%Y-%m-%d")
| dedup EBNCStatus Day
| table EBNCStatus True Day&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 10:12:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657572#M54174</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-14T10:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657576#M54175</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have selected last 7 days&amp;nbsp;&lt;/P&gt;&lt;P&gt;but its showing only 2 with below query&lt;/P&gt;&lt;P&gt;index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"&lt;BR /&gt;| eval&lt;BR /&gt;True=if(searchmatch("ebnc event balanced successfully"),"✔",""),&lt;BR /&gt;EBNCStatus="ebnc event balanced successfully",&lt;BR /&gt;Day=strftime(_time,"%Y-%m-%d")&lt;BR /&gt;| dedup EBNCStatus Day&lt;BR /&gt;| table EBNCStatus True Day&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 10:28:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657576#M54175</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-14T10:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657592#M54176</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please guide me on this .&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 12:10:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657592#M54176</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-14T12:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657595#M54178</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you try my last answer?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 12:14:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657595#M54178</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-14T12:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657596#M54179</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes but with that I am only getting two message&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have selected last 7 days and I am getting only two.&lt;/P&gt;&lt;P&gt;I want if I select last 7 it should show 7 message&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I select yesterday it should show 1 message.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 12:17:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657596#M54179</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-14T12:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657598#M54180</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apologies the query is working but I am getting one additional row .&lt;/P&gt;&lt;P&gt;My query:&lt;/P&gt;&lt;P&gt;search index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"&lt;BR /&gt;| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")&lt;BR /&gt;| eval EBNCStatus="ebnc event balanced successfully",Day=strftime(_time,"%Y-%m-%d")| dedup EBNCStatus Day&lt;BR /&gt;| table EBNCStatus True Day&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aditsss_0-1694694520509.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27180iFBE9B3C5D9E83F50/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aditsss_0-1694694520509.png" alt="aditsss_0-1694694520509.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 12:28:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657598#M54180</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-14T12:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657613#M54181</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what's the name of the first column?&lt;/P&gt;&lt;P&gt;if it's "&lt;SPAN&gt;EBNCStatus",&amp;nbsp;&lt;/SPAN&gt;put the condition&amp;nbsp;&lt;SPAN&gt;EBNCStatus=* at the end of the search.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 13:13:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657613#M54181</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-14T13:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657623#M54182</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This query is not working for me&lt;/P&gt;&lt;P&gt;index="abc" sourcetype =600000304_gg_abs_ipc2 source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"&lt;BR /&gt;| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")&lt;BR /&gt;| eval EBNCStatus=*"ebnc event balanced successfully",Day=strftime(_time,"%Y-%m-%d")| dedup EBNCStatus Day&lt;BR /&gt;| table EBNCStatus True Day&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 14:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657623#M54182</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-14T14:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657630#M54183</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;where I need to put this&amp;nbsp;&lt;SPAN&gt;EBNCStatus=*&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Below is my query:&lt;/P&gt;&lt;P&gt;index="abc" sourcetype =600000304_gg_abs_ipc2 source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"&lt;BR /&gt;| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")&lt;BR /&gt;| eval EBNCStatus="ebnc event balanced successfully",Day=strftime(_time,"%Y-%m-%d")| dedup EBNCStatus Day&lt;BR /&gt;| table EBNCStatus True Day&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 14:53:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657630#M54183</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-14T14:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657634#M54184</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you don't want the last row with some empty fields, you have to remove empty lines.&lt;/P&gt;&lt;P&gt;You can do it knowing the name of the first column (that I don't know) and poning a rule (if the column is called "column1":&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="abc" sourcetype =600000304_gg_abs_ipc2 source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"
| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")
| eval EBNCStatus=*"ebnc event balanced successfully",Day=strftime(_time,"%Y-%m-%d")
| dedup EBNCStatus Day
| search column1=*
| table EBNCStatus True Day&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 14:59:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657634#M54184</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-14T14:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657643#M54185</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried below query&lt;/P&gt;&lt;P&gt;index=abc sourcetype =600000304_gg_abs_ipc2 source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"&lt;BR /&gt;| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")&lt;BR /&gt;| eval EBNCStatus=*"ebnc event balanced successfully",Day=strftime(_time,"%Y-%m-%d")&lt;BR /&gt;| dedup EBNCStatus Day&lt;BR /&gt;| search column1=*&lt;BR /&gt;| table EBNCStatus True Day&lt;/P&gt;&lt;P&gt;Getting below error&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Error in 'EvalCommand': The expression is malformed. An unexpected character is reached at '*"ebnc event balanced successfully",Day=strftime(_time,"%Y-%m-%d")'.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 16:29:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657643#M54185</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-14T16:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657686#M54189</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066" target="_blank"&gt;@aditsss&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;if you don't want the last row with some empty fields, you have to remove empty lines.&lt;/P&gt;&lt;P&gt;You can do it knowing the name of the first column (that I don't know) and poning a rule (if the column is called "column1":&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="abc" sourcetype =600000304_gg_abs_ipc2 source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"
| eval 
   True=if(searchmatch("ebnc event balanced successfully"),"✔",""),
   EBNCStatus="ebnc event balanced successfully",
   Day=strftime(_time,"%Y-%m-%d")
| dedup EBNCStatus Day
| search column1=*
| table EBNCStatus True Day&lt;/LI-CODE&gt;&lt;P&gt;there is an asterisk outside the quotes in the second eval.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 06:17:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657686#M54189</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-15T06:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657978#M54213</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried with below query still one extra row is coming&lt;/P&gt;&lt;P&gt;index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"&lt;BR /&gt;| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")&lt;BR /&gt;| eval EBNCStatus="ebnc event balanced successfully",Day=strftime(_time,"%Y-%m-%d")| dedup EBNCStatus Day|search EBNCStatus=*&lt;BR /&gt;| table EBNCStatus True Day&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 10:28:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657978#M54213</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-19T10:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657980#M54214</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you have an empty field using the table command means that you have incomplete data or that you have a space in that field.&lt;/P&gt;&lt;P&gt;anyway, you can remove them using a different search, e.g. if all the&amp;nbsp;&lt;SPAN&gt;EBNCStatus values starts with "ebnc, you could use&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search EBNCStatus="ebnc*"&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 10:38:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657980#M54214</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-19T10:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657992#M54215</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you guide me with this query how can I use it&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;| eval EBNCStatus="ebnc event balanced successfully",Day=strftime(_time,"%Y-%m-%d")| dedup EBNCStatus Day|search EBNCStatus=*&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;| table EBNCStatus True Day&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 12:39:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657992#M54215</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-09-19T12:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit instance according to drop down value selected for date filter</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657996#M54217</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;can you confirm that the values in the field EBNCStatus always starts with "ebnc"?&lt;/P&gt;&lt;P&gt;if yes, please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "ReadFileImpl - ebnc event balanced successfully"
| eval True=if(searchmatch("ebnc event balanced successfully"),"✔","")
| eval EBNCStatus="ebnc event balanced successfully",Day=strftime(_time,"%Y-%m-%d")| dedup EBNCStatus Day
| search EBNCStatus="ebnc*"
| table EBNCStatus True Day&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 13:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-limit-instance-according-to-drop-down-value-selected-for/m-p/657996#M54217</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-19T13:01:34Z</dc:date>
    </item>
  </channel>
</rss>

