<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to pass multiselect token values from main dashboard A to drilldown dashboard B in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/520064#M146439</link>
    <description>&lt;P&gt;I am not sure what you mean by transferred/applied. The multiselect can set up tokens in the change event that can be used elsewhere in the dashboard e.g. the drilldown target panel. Also, if you want the multiselect in the drilldown panel to be populated with the choices from the main multiselect you can do something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;input type="multiselect" token="projects" searchWhenChanged="false"&amp;gt;
&amp;lt;label&amp;gt;Projects&amp;lt;/label&amp;gt;
&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
&amp;lt;fieldForLabel&amp;gt;Projects&amp;lt;/fieldForLabel&amp;gt;
&amp;lt;fieldForValue&amp;gt;Projects&amp;lt;/fieldForValue&amp;gt;
&amp;lt;search base="sample"&amp;gt;
&amp;lt;query&amp;gt;| search Organization="$organization$"
| stats dc(Projects) AS Total by Projects
| fields - Total&amp;lt;/query&amp;gt;
&amp;lt;/search&amp;gt;
&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
&amp;lt;prefix&amp;gt;Projects IN (&amp;lt;/prefix&amp;gt;
&amp;lt;suffix&amp;gt;)&amp;lt;/suffix&amp;gt;
&amp;lt;delimiter&amp;gt;,&amp;lt;/delimiter&amp;gt;
&amp;lt;valuePrefix&amp;gt;"&amp;lt;/valuePrefix&amp;gt;
&amp;lt;valueSuffix&amp;gt;"&amp;lt;/valueSuffix&amp;gt;
&amp;lt;change&amp;gt;
&amp;lt;eval token="form.drilldownmulti"&amp;gt;'form.projects'&amp;lt;/eval&amp;gt;
&amp;lt;/change&amp;gt;
&amp;lt;/input&amp;gt;
&amp;lt;input type="multiselect" token="drilldownmulti"&amp;gt;
&amp;lt;label&amp;gt;Drilldown&amp;lt;/label&amp;gt;
&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;prefix&amp;gt;Projects IN (&amp;lt;/prefix&amp;gt;
&amp;lt;suffix&amp;gt;)&amp;lt;/suffix&amp;gt;
&amp;lt;delimiter&amp;gt;,&amp;lt;/delimiter&amp;gt;
&amp;lt;valuePrefix&amp;gt;"&amp;lt;/valuePrefix&amp;gt;
&amp;lt;valueSuffix&amp;gt;"&amp;lt;/valueSuffix&amp;gt;
&amp;lt;/input&amp;gt;&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 17 Sep 2020 07:59:23 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2020-09-17T07:59:23Z</dc:date>
    <item>
      <title>How to pass multiselect token values from main dashboard A to drilldown dashboard B</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/520041#M146431</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a simple multi-select filter as below on my main dashboard.&lt;/P&gt;&lt;PRE&gt;&amp;lt;input type="multiselect" token="projects" searchWhenChanged="false"&amp;gt;
&amp;lt;label&amp;gt;Projects&amp;lt;/label&amp;gt;
&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
&amp;lt;fieldForLabel&amp;gt;Projects&amp;lt;/fieldForLabel&amp;gt;
&amp;lt;fieldForValue&amp;gt;Projects&amp;lt;/fieldForValue&amp;gt;
&amp;lt;search base="sample"&amp;gt;
&amp;lt;query&amp;gt;| search Organization="$organization$"
| stats dc(Projects) AS Total by Projects
| fields - Total&amp;lt;/query&amp;gt;
&amp;lt;/search&amp;gt;
&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
&amp;lt;prefix&amp;gt;Projects IN (&amp;lt;/prefix&amp;gt;
&amp;lt;suffix&amp;gt;)&amp;lt;/suffix&amp;gt;
&amp;lt;delimiter&amp;gt;,&amp;lt;/delimiter&amp;gt;
&amp;lt;valuePrefix&amp;gt;"&amp;lt;/valuePrefix&amp;gt;
&amp;lt;valueSuffix&amp;gt;"&amp;lt;/valueSuffix&amp;gt;
&amp;lt;/input&amp;gt;&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;When dashboard populates and users select Projects using multiselect filter above, it gives them a list of vulnerabilities affecting assets in selected projects. Now, when users click on one of the vulnerabilities of their choice, it takes them to drill down dashboard which has some more multi select filters including one like above.&lt;/P&gt;&lt;P&gt;What I need is when users go to drill down dashboard, I need selected Projects from main dashboard A to be transferred/applied to drill-down dashboard B.&lt;/P&gt;&lt;P&gt;Thanks in-advance.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 02:30:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/520041#M146431</guid>
      <dc:creator>mbasharat</dc:creator>
      <dc:date>2020-09-17T02:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to pass multiselect token values from main dashboard A to drilldown dashboard B</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/520064#M146439</link>
      <description>&lt;P&gt;I am not sure what you mean by transferred/applied. The multiselect can set up tokens in the change event that can be used elsewhere in the dashboard e.g. the drilldown target panel. Also, if you want the multiselect in the drilldown panel to be populated with the choices from the main multiselect you can do something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;input type="multiselect" token="projects" searchWhenChanged="false"&amp;gt;
&amp;lt;label&amp;gt;Projects&amp;lt;/label&amp;gt;
&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
&amp;lt;fieldForLabel&amp;gt;Projects&amp;lt;/fieldForLabel&amp;gt;
&amp;lt;fieldForValue&amp;gt;Projects&amp;lt;/fieldForValue&amp;gt;
&amp;lt;search base="sample"&amp;gt;
&amp;lt;query&amp;gt;| search Organization="$organization$"
| stats dc(Projects) AS Total by Projects
| fields - Total&amp;lt;/query&amp;gt;
&amp;lt;/search&amp;gt;
&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
&amp;lt;prefix&amp;gt;Projects IN (&amp;lt;/prefix&amp;gt;
&amp;lt;suffix&amp;gt;)&amp;lt;/suffix&amp;gt;
&amp;lt;delimiter&amp;gt;,&amp;lt;/delimiter&amp;gt;
&amp;lt;valuePrefix&amp;gt;"&amp;lt;/valuePrefix&amp;gt;
&amp;lt;valueSuffix&amp;gt;"&amp;lt;/valueSuffix&amp;gt;
&amp;lt;change&amp;gt;
&amp;lt;eval token="form.drilldownmulti"&amp;gt;'form.projects'&amp;lt;/eval&amp;gt;
&amp;lt;/change&amp;gt;
&amp;lt;/input&amp;gt;
&amp;lt;input type="multiselect" token="drilldownmulti"&amp;gt;
&amp;lt;label&amp;gt;Drilldown&amp;lt;/label&amp;gt;
&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;prefix&amp;gt;Projects IN (&amp;lt;/prefix&amp;gt;
&amp;lt;suffix&amp;gt;)&amp;lt;/suffix&amp;gt;
&amp;lt;delimiter&amp;gt;,&amp;lt;/delimiter&amp;gt;
&amp;lt;valuePrefix&amp;gt;"&amp;lt;/valuePrefix&amp;gt;
&amp;lt;valueSuffix&amp;gt;"&amp;lt;/valueSuffix&amp;gt;
&amp;lt;/input&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 17 Sep 2020 07:59:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/520064#M146439</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-17T07:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to pass multiselect token values from main dashboard A to drilldown dashboard B</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/520146#M146468</link>
      <description>&lt;P&gt;Hi&amp;nbsp;@&amp;nbsp;ITWhisperer,&lt;/P&gt;&lt;P&gt;After looking at your code, what is mean to ask originally is:&lt;/P&gt;&lt;UL class="lia-list-style-type-circle"&gt;&lt;LI&gt;There are two dashboards, &lt;STRONG&gt;Main Dashboard&lt;/STRONG&gt; and &lt;STRONG&gt;Drilldown Dashboard&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Projects multiselect filter menus exist on both.&lt;/LI&gt;&lt;LI&gt;I have a stats table/panel on Main dashboard with drilldown enabled. This stats table/panel is dependent on Projects multiselect filter.&lt;/LI&gt;&lt;LI&gt;If there are multiple Project values selected in multiselect on Main Dashboard e.g. Project A, Project B, Project C then if I click my choice of row in a stats table/panel on Main Dashboard,&amp;nbsp; drilldown takes me to Drilldown Dashboard. When this drill down happens, I need selected Projects in multiselect menu filter on Main Dashboard to be passed over to Projects multiselect menu filter on Drill down dashboard with values Project A, Project B, Project C&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I hope I explained it clearly. Thanks in-advance!!! Awaiting response.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 13:49:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/520146#M146468</guid>
      <dc:creator>mbasharat</dc:creator>
      <dc:date>2020-09-17T13:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to pass multiselect token values from main dashboard A to drilldown dashboard B</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/520177#M146478</link>
      <description>&lt;P&gt;OK I understand - it is the good old passing multi value tokens which keeps cropping up. Try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;input type="multiselect" token="projects" searchWhenChanged="false"&amp;gt;
&amp;lt;label&amp;gt;Projects&amp;lt;/label&amp;gt;
&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
&amp;lt;fieldForLabel&amp;gt;Projects&amp;lt;/fieldForLabel&amp;gt;
&amp;lt;fieldForValue&amp;gt;Projects&amp;lt;/fieldForValue&amp;gt;
&amp;lt;search base="sample"&amp;gt;
&amp;lt;query&amp;gt;| search Organization="$organization$"
| stats dc(Projects) AS Total by Projects
| fields - Total&amp;lt;/query&amp;gt;
&amp;lt;/search&amp;gt;
&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
&amp;lt;prefix&amp;gt;Projects IN (&amp;lt;/prefix&amp;gt;
&amp;lt;suffix&amp;gt;)&amp;lt;/suffix&amp;gt;
&amp;lt;delimiter&amp;gt;,&amp;lt;/delimiter&amp;gt;
&amp;lt;valuePrefix&amp;gt;"&amp;lt;/valuePrefix&amp;gt;
&amp;lt;valueSuffix&amp;gt;"&amp;lt;/valueSuffix&amp;gt;
&amp;lt;change&amp;gt;
&amp;lt;eval token="drilldownmulti"&amp;gt;mvjoin('form.projects',"&amp;amp;amp;form.drilldownmulti=")&amp;lt;/eval&amp;gt;
&amp;lt;/change&amp;gt;
&amp;lt;/input&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;Then in stats table panel:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;drilldown&amp;gt;
&amp;lt;link target="_blank"&amp;gt;/app/yourapp/drilldown?form.drilldownmulti=$drilldownmulti|n$&amp;lt;/link&amp;gt;
&amp;lt;/drilldown&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;Then in drilldown dashboard:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;input type="multiselect" token="drilldownmulti"&amp;gt;
&amp;lt;label&amp;gt;Drilldown&amp;lt;/label&amp;gt;
&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
&amp;lt;prefix&amp;gt;Projects IN (&amp;lt;/prefix&amp;gt;
&amp;lt;suffix&amp;gt;)&amp;lt;/suffix&amp;gt;
&amp;lt;delimiter&amp;gt;,&amp;lt;/delimiter&amp;gt;
&amp;lt;valuePrefix&amp;gt;"&amp;lt;/valuePrefix&amp;gt;
&amp;lt;valueSuffix&amp;gt;"&amp;lt;/valueSuffix&amp;gt;
&amp;lt;/input&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;Things to note: "|n" at the end of the link, and no default to the drilldown multiselect and the should be at least 1 choice.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 16:34:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/520177#M146478</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-17T16:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to pass multiselect token values from main dashboard A to drilldown dashboard B</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/521358#M146915</link>
      <description>&lt;P&gt;H&amp;nbsp;@ ITWhisperer,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Quick question, for one filter which was my original ask, this solution works great. But when I have tried to use it with multiple filters for multiple fields to be passed, it is not. What am I missing pls? I did adjust the logic as in this solution for the rest. Thanks!!!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 19:14:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/521358#M146915</guid>
      <dc:creator>mbasharat</dc:creator>
      <dc:date>2020-09-24T19:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to pass multiselect token values from main dashboard A to drilldown dashboard B</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/521370#M146921</link>
      <description>&lt;P&gt;You haven't said what it was that you did for multiple dropdowns to be passed, or what didn't work, but assuming the other mv, let's call it othermulti, is setup a similar way, the difference in the drilldown url would be something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;drilldown&amp;gt;
&amp;lt;link target="_blank"&amp;gt;/app/yourapp/drilldown?form.drilldownmulti=$drilldownmulti|n$&amp;amp;amp;form.othermulti=$othermulti|n$&amp;lt;/link&amp;gt;
&amp;lt;/drilldown&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 20:22:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/521370#M146921</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-24T20:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to pass multiselect token values from main dashboard A to drilldown dashboard B</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/521650#M147008</link>
      <description>&lt;P&gt;Hi&amp;nbsp;@ ITWhisperer,&lt;/P&gt;&lt;P&gt;Sorry, I was away from home. Will be posting my code snippet for filters today. Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 27 Sep 2020 17:27:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/521650#M147008</guid>
      <dc:creator>mbasharat</dc:creator>
      <dc:date>2020-09-27T17:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to pass multiselect token values from main dashboard A to drilldown dashboard B</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/522145#M147220</link>
      <description>&lt;P&gt;Hi&amp;nbsp;@ ITWhisperer,&lt;/P&gt;&lt;P&gt;So I used your method below,&amp;nbsp; made progress and multiselect started passing the value from multiselect filter from dashboard A and drilldown stats table panel to filters in dashboard B.&amp;nbsp; Now the issue is, the value that is selected on dashboard A is not the one that is getting transferred to dashboard B. A different value is getting passed which seems odd because the selected one needs to be passed over.&lt;/P&gt;&lt;P&gt;Here is my code snippet for the filters:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Dashboard A:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;    &amp;lt;input type="dropdown" token="scantype" searchWhenChanged="false"&amp;gt;
      &amp;lt;label&amp;gt;Scan Type&amp;lt;/label&amp;gt;
      &amp;lt;fieldForLabel&amp;gt;Scan_Type&amp;lt;/fieldForLabel&amp;gt;
      &amp;lt;fieldForValue&amp;gt;Scan_Type&amp;lt;/fieldForValue&amp;gt;
      &amp;lt;search base="menus"&amp;gt;
        &amp;lt;query&amp;gt;| stats dc(Scan_Type) AS Total by Scan_Type
| fields - Total&amp;lt;/query&amp;gt;
      &amp;lt;/search&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
      &amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="multiselect" token="resporg" searchWhenChanged="false"&amp;gt;
      &amp;lt;label&amp;gt;Responsible Organization&amp;lt;/label&amp;gt;
      &amp;lt;fieldForLabel&amp;gt;Responsible_Organization&amp;lt;/fieldForLabel&amp;gt;
      &amp;lt;fieldForValue&amp;gt;Responsible_Organization&amp;lt;/fieldForValue&amp;gt;
      &amp;lt;search base="menus"&amp;gt;
        &amp;lt;query&amp;gt;| search Scan_Type="$scantype$"
| stats dc(Responsible_Organization) AS Total by Responsible_Organization
| fields - Total&amp;lt;/query&amp;gt;
      &amp;lt;/search&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
      &amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
      &amp;lt;prefix&amp;gt;Responsible_Organization IN (&amp;lt;/prefix&amp;gt;
      &amp;lt;suffix&amp;gt;)&amp;lt;/suffix&amp;gt;
      &amp;lt;valuePrefix&amp;gt;"&amp;lt;/valuePrefix&amp;gt;
      &amp;lt;valueSuffix&amp;gt;"&amp;lt;/valueSuffix&amp;gt;
      &amp;lt;delimiter&amp;gt;,&amp;lt;/delimiter&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;eval token="drilldownmultiorg"&amp;gt;mvjoin('form.resporg',"&amp;amp;amp;form.drilldownmultiorg=")&amp;lt;/eval&amp;gt;
      &amp;lt;/change&amp;gt;
    &amp;lt;/input&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Stats Panel A:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;drilldown&amp;gt;
&amp;lt;link target="_blank"&amp;gt;/app/sample_app/drilldown_dashboard?form.cves=$row.CVE$&amp;amp;amp;form.scantype=$scantype$&amp;amp;amp;form.resporg=$drilldownmultiorg|n$&amp;lt;/link&amp;gt;
&amp;lt;/drilldown&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Dashboard B:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; &amp;lt;input type="text" token="cves"&amp;gt;
      &amp;lt;label&amp;gt;Select CVE&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;CVE-2015-6550&amp;lt;/default&amp;gt;
      &amp;lt;initialValue&amp;gt;CVE-2015-6550&amp;lt;/initialValue&amp;gt;
 &amp;lt;/input&amp;gt;
 &amp;lt;input type="multiselect" token="plugin" searchWhenChanged="false"&amp;gt;
      &amp;lt;label&amp;gt;Plugin ID/s&amp;lt;/label&amp;gt;
      &amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
      &amp;lt;fieldForLabel&amp;gt;Plugin_ID&amp;lt;/fieldForLabel&amp;gt;
      &amp;lt;fieldForValue&amp;gt;Plugin_ID&amp;lt;/fieldForValue&amp;gt;
      &amp;lt;search base="vulninfo"&amp;gt;
        &amp;lt;query&amp;gt;| search CVE="$cves$"
| stats dc(Plugin_ID) AS count BY Plugin_ID
| fields Plugin_ID&amp;lt;/query&amp;gt;
      &amp;lt;/search&amp;gt;
      &amp;lt;prefix&amp;gt;Plugin_ID IN (&amp;lt;/prefix&amp;gt;
      &amp;lt;suffix&amp;gt;)&amp;lt;/suffix&amp;gt;
      &amp;lt;delimiter&amp;gt;,&amp;lt;/delimiter&amp;gt;
      &amp;lt;valuePrefix&amp;gt;"&amp;lt;/valuePrefix&amp;gt;
      &amp;lt;valueSuffix&amp;gt;"&amp;lt;/valueSuffix&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="dropdown" token="scantype" searchWhenChanged="false"&amp;gt;
      &amp;lt;label&amp;gt;Scan Type&amp;lt;/label&amp;gt;
      &amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
      &amp;lt;fieldForLabel&amp;gt;Scan_Type&amp;lt;/fieldForLabel&amp;gt;
      &amp;lt;fieldForValue&amp;gt;Scan_Type&amp;lt;/fieldForValue&amp;gt;
      &amp;lt;search base="vulninfo"&amp;gt;
        &amp;lt;query&amp;gt;| search CVE="$cves$" AND $plugin$
| stats dc(Scan_Type) AS count BY Scan_Type
| fields Scan_Type&amp;lt;/query&amp;gt;
      &amp;lt;/search&amp;gt;
&amp;lt;/input&amp;gt;
    &amp;lt;input type="multiselect" token="drilldownmultiorg" searchWhenChanged="false"&amp;gt;
      &amp;lt;label&amp;gt;Responsbile Organization&amp;lt;/label&amp;gt;
      &amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
      &amp;lt;fieldForLabel&amp;gt;KISAM_Responsible_Organization&amp;lt;/fieldForLabel&amp;gt;
      &amp;lt;fieldForValue&amp;gt;KISAM_Responsible_Organization&amp;lt;/fieldForValue&amp;gt;
      &amp;lt;search base="vulninfo"&amp;gt;
        &amp;lt;query&amp;gt;| search CVE="$cves$" AND $plugin$ AND Scan_Type="$scantype$"
| stats dc(KISAM_Responsible_Organization) AS count BY KISAM_Responsible_Organization
| fields KISAM_Responsible_Organization&amp;lt;/query&amp;gt;
&amp;lt;/search&amp;gt;
      &amp;lt;prefix&amp;gt;KISAM_Responsible_Organization IN (&amp;lt;/prefix&amp;gt;
      &amp;lt;suffix&amp;gt;)&amp;lt;/suffix&amp;gt;
      &amp;lt;valuePrefix&amp;gt;"&amp;lt;/valuePrefix&amp;gt;
      &amp;lt;valueSuffix&amp;gt;"&amp;lt;/valueSuffix&amp;gt;
      &amp;lt;delimiter&amp;gt;,&amp;lt;/delimiter&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:04:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/522145#M147220</guid>
      <dc:creator>mbasharat</dc:creator>
      <dc:date>2020-09-30T05:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to pass multiselect token values from main dashboard A to drilldown dashboard B</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/522180#M147233</link>
      <description>&lt;P&gt;Working from the bottom up, in Dashboard B, the multiselect may not need a search to populate it since we are passing in the values&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;    &amp;lt;input type="multiselect" token="drilldownmultiorg" searchWhenChanged="false"&amp;gt;
      &amp;lt;label&amp;gt;Responsbile Organization&amp;lt;/label&amp;gt;
      &amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
      &amp;lt;prefix&amp;gt;KISAM_Responsible_Organization IN (&amp;lt;/prefix&amp;gt;
      &amp;lt;suffix&amp;gt;)&amp;lt;/suffix&amp;gt;
      &amp;lt;valuePrefix&amp;gt;"&amp;lt;/valuePrefix&amp;gt;
      &amp;lt;valueSuffix&amp;gt;"&amp;lt;/valueSuffix&amp;gt;
      &amp;lt;delimiter&amp;gt;,&amp;lt;/delimiter&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;The stats panel drilldown in Dashboard A needs to pass the values to&amp;nbsp;form.drilldownmultiorg&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;drilldown&amp;gt;
&amp;lt;link target="_blank"&amp;gt;/app/sample_app/drilldown_dashboard?form.cves=$row.CVE$&amp;amp;amp;form.scantype=$scantype$&amp;amp;amp;form.drilldownmultiorg=$drilldownmultiorg|n$&amp;lt;/link&amp;gt;
&amp;lt;/drilldown&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;In all cases, your queries to populate the dropdowns can be simplified to remove the stats, for example&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;        &amp;lt;query&amp;gt;| dedup Scan_Type | fields Scan_Type&amp;lt;/query&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 07:58:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/522180#M147233</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-30T07:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to pass multiselect token values from main dashboard A to drilldown dashboard B</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/522248#M147259</link>
      <description>&lt;P&gt;dedup does not work for me because I am dealing with a lot of data and stats runs the fastest.&lt;/P&gt;&lt;P&gt;The drilldown dashboard is also used as an individual dashboard.&lt;/P&gt;&lt;P&gt;USing your approach, tokens do get transferred now. The problem is if a value A is selected on dashboard A, filter logic is passing on value C or D. There is something in |n logic or something else causing this which I am not getting.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 12:48:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/522248#M147259</guid>
      <dc:creator>mbasharat</dc:creator>
      <dc:date>2020-09-30T12:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to pass multiselect token values from main dashboard A to drilldown dashboard B</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/750335#M242291</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Tested it and is working&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 12:38:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-multiselect-token-values-from-main-dashboard-A-to/m-p/750335#M242291</guid>
      <dc:creator>Boozhie</dc:creator>
      <dc:date>2025-07-23T12:38:49Z</dc:date>
    </item>
  </channel>
</rss>

