<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search feed by hiddensearch in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-feed-by-hiddensearch/m-p/134431#M8017</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a form where one enters an IP address. This address is used by several searches to fill the dashboard panels. For one panel I need the dns name and not the IP address for the search. Is it possible to do a hidden search first (and do the nslookup) and use this information inside the main search?&lt;/P&gt;

&lt;P&gt;I can't do the nslookup inside my main search because the main search starts with a custom command that HAS to be the first command.&lt;/P&gt;

&lt;P&gt;Thanks for your help!&lt;/P&gt;

&lt;P&gt;Kind regards,&lt;BR /&gt;
Felix&lt;/P&gt;</description>
    <pubDate>Fri, 08 Nov 2013 13:13:06 GMT</pubDate>
    <dc:creator>fbl_itcs</dc:creator>
    <dc:date>2013-11-08T13:13:06Z</dc:date>
    <item>
      <title>Search feed by hiddensearch</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-feed-by-hiddensearch/m-p/134431#M8017</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a form where one enters an IP address. This address is used by several searches to fill the dashboard panels. For one panel I need the dns name and not the IP address for the search. Is it possible to do a hidden search first (and do the nslookup) and use this information inside the main search?&lt;/P&gt;

&lt;P&gt;I can't do the nslookup inside my main search because the main search starts with a custom command that HAS to be the first command.&lt;/P&gt;

&lt;P&gt;Thanks for your help!&lt;/P&gt;

&lt;P&gt;Kind regards,&lt;BR /&gt;
Felix&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2013 13:13:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-feed-by-hiddensearch/m-p/134431#M8017</guid>
      <dc:creator>fbl_itcs</dc:creator>
      <dc:date>2013-11-08T13:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: Search feed by hiddensearch</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-feed-by-hiddensearch/m-p/134432#M8018</link>
      <description>&lt;P&gt;You could add a Search module and  a ResultValueSetter module to have a variable. The only thing to ensure here is the panel which will be using this should be defined within scope of this search and resultvaluesetter. This search will be hidden.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;module name="Search"&amp;gt;
    &amp;lt;param name="search"&amp;gt;
*|head 1| eval hostIp="$YourIPTextBoxName$" | table hostIp  | lookup dnslookup clientip as hostIp |rename clienthost as HostName|table HostName
    &amp;lt;/param&amp;gt;                
    &amp;lt;module name="ResultsValueSetter"&amp;gt;
        &amp;lt;param name="fields"&amp;gt;HostName&amp;lt;/param&amp;gt;
        ...
        ...
        &amp;lt;module name="Search" layoutPanel="panel_row2_col1"&amp;gt;
        ...Your Search Code Here
        &amp;lt;/module&amp;gt;
        ...
        ...
    &amp;lt;/module&amp;gt;
&amp;lt;/module&amp;gt;                   
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 08 Nov 2013 14:34:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-feed-by-hiddensearch/m-p/134432#M8018</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2013-11-08T14:34:24Z</dc:date>
    </item>
  </channel>
</rss>

