<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set a splunk token in a search query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-splunk-token-in-a-search-query/m-p/513184#M143978</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used this line in my panel search below&lt;/P&gt;&lt;PRE&gt;| where match(User_Name,"$user_name$")&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_qns4_p1.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10138i371621726ACB488B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk_qns4_p1.PNG" alt="splunk_qns4_p1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And i used the same token in my dropdown field so that i when i select the values from the dropdown field, it will appear in the panel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_qns4_p2.PNG" style="width: 331px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10139i5F9CE879FB3060DD/image-dimensions/331x361?v=v2" width="331" height="361" role="button" title="splunk_qns4_p2.PNG" alt="splunk_qns4_p2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i cancelled the search in the dropdown function, i was supposed to get back all the user accounts with failed logins like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_qns4_p3.PNG" style="width: 567px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10140iEE598AEF54235C71/image-dimensions/567x180?v=v2" width="567" height="180" role="button" title="splunk_qns4_p3.PNG" alt="splunk_qns4_p3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Instead, I got this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_qns4_p4.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10141iCAA09E17256861ED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk_qns4_p4.PNG" alt="splunk_qns4_p4.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do i get rid of this error?&lt;/P&gt;</description>
    <pubDate>Sun, 09 Aug 2020 04:30:03 GMT</pubDate>
    <dc:creator>rkris</dc:creator>
    <dc:date>2020-08-09T04:30:03Z</dc:date>
    <item>
      <title>How to set a splunk token in a search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-splunk-token-in-a-search-query/m-p/512253#M143662</link>
      <description>&lt;P&gt;I've created a text form input called 'username' to search for usernames in my dashboard panels and i've set the token value to 'user_name'&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_qns1.PNG" style="width: 256px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10008i63DF4E3B2CE37007/image-dimensions/256x247?v=v2" width="256" height="247" role="button" title="splunk_qns1.PNG" alt="splunk_qns1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now, I'm trying to add the above token value to this search string which filters out all the users with failed logins&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_qns1a.PNG" style="width: 565px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10009iBA4B070F10CEE651/image-dimensions/565x161?v=v2" width="565" height="161" role="button" title="splunk_qns1a.PNG" alt="splunk_qns1a.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But, I'm not sure how to add the token to this search query. Does anyone know how to do this?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 03:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-splunk-token-in-a-search-query/m-p/512253#M143662</guid>
      <dc:creator>rkris</dc:creator>
      <dc:date>2020-08-04T03:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a splunk token in a search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-splunk-token-in-a-search-query/m-p/512255#M143664</link>
      <description>&lt;P&gt;Just add the following line after your rex statement&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where match(User_Name,"$user_name$")

OR

| where match(User_Name,"(?i)$user_name$")&lt;/LI-CODE&gt;&lt;P&gt;The second will do a case insensitive match. Note that this is a partial match. Use any of the regex qualifiers to enhance the search as needed, such as ^ and $ to match the start and end for complete matches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 03:24:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-splunk-token-in-a-search-query/m-p/512255#M143664</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2020-08-04T03:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a splunk token in a search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-splunk-token-in-a-search-query/m-p/513184#M143978</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used this line in my panel search below&lt;/P&gt;&lt;PRE&gt;| where match(User_Name,"$user_name$")&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_qns4_p1.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10138i371621726ACB488B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk_qns4_p1.PNG" alt="splunk_qns4_p1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And i used the same token in my dropdown field so that i when i select the values from the dropdown field, it will appear in the panel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_qns4_p2.PNG" style="width: 331px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10139i5F9CE879FB3060DD/image-dimensions/331x361?v=v2" width="331" height="361" role="button" title="splunk_qns4_p2.PNG" alt="splunk_qns4_p2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i cancelled the search in the dropdown function, i was supposed to get back all the user accounts with failed logins like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_qns4_p3.PNG" style="width: 567px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10140iEE598AEF54235C71/image-dimensions/567x180?v=v2" width="567" height="180" role="button" title="splunk_qns4_p3.PNG" alt="splunk_qns4_p3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Instead, I got this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk_qns4_p4.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10141iCAA09E17256861ED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk_qns4_p4.PNG" alt="splunk_qns4_p4.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do i get rid of this error?&lt;/P&gt;</description>
      <pubDate>Sun, 09 Aug 2020 04:30:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-splunk-token-in-a-search-query/m-p/513184#M143978</guid>
      <dc:creator>rkris</dc:creator>
      <dc:date>2020-08-09T04:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a splunk token in a search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-splunk-token-in-a-search-query/m-p/513228#M143984</link>
      <description>&lt;P&gt;When you get the 'waiting for input' and you are using tokens, it generally means the token has not been set, so the search that uses the token will not run.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure why you are seeing that, but I am not sure what you mean by cancelling the dropdown search...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Aug 2020 23:15:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-splunk-token-in-a-search-query/m-p/513228#M143984</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2020-08-09T23:15:59Z</dc:date>
    </item>
  </channel>
</rss>

