<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Set token from dropdown in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Set-token-from-dropdown/m-p/535782#M151440</link>
    <description>&lt;P&gt;You need client and client_id in the table returned by the query and I think you have the label and value fields the wrong way around. Try something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;input type="dropdown" token="clientId" searchWhenChanged="true"&amp;gt;
&amp;lt;label&amp;gt;Integrator&amp;lt;/label&amp;gt;
&amp;lt;fieldForLabel&amp;gt;client&amp;lt;/fieldForLabel&amp;gt;
&amp;lt;fieldForValue&amp;gt;client_id&amp;lt;/fieldForValue&amp;gt;
&amp;lt;search&amp;gt;
&amp;lt;query&amp;gt;basic search | lookup clients client_id as client_id OUTPUTNEW client_name client_id
| eval client = client_name +"(" + client_id +")" | dedup client
| table client_id client&amp;lt;/query&amp;gt;
&amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
&amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
&amp;lt;/search&amp;gt;
&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;/input&amp;gt;&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 14 Jan 2021 08:47:16 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-01-14T08:47:16Z</dc:date>
    <item>
      <title>Set token from dropdown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Set-token-from-dropdown/m-p/535764#M151435</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a dropdown with dynamic query&lt;/P&gt;&lt;P&gt;&amp;lt;input type="dropdown" token="clientId" searchWhenChanged="true"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Integrator&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;fieldForLabel&amp;gt;client_id&amp;lt;/fieldForLabel&amp;gt;&lt;BR /&gt;&amp;lt;fieldForValue&amp;gt;client&amp;lt;/fieldForValue&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;basic search | lookup clients client_id as client_id OUTPUTNEW client_name client_id&lt;BR /&gt;| eval client = client_name +"(" + client_id +")" | dedup client&lt;BR /&gt;| table client&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;/P&gt;&lt;P&gt;For display dropdown in dashboard, I want exactly like: clientName(Client_id) ex: Tester(123).&lt;/P&gt;&lt;P&gt;but in panel queries I want only clientId in a token, no clientName.&lt;/P&gt;&lt;P&gt;any help would be appreciated.&lt;/P&gt;&lt;P&gt;thanks !!!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 06:27:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Set-token-from-dropdown/m-p/535764#M151435</guid>
      <dc:creator>smahuja</dc:creator>
      <dc:date>2021-01-14T06:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Set token from dropdown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Set-token-from-dropdown/m-p/535782#M151440</link>
      <description>&lt;P&gt;You need client and client_id in the table returned by the query and I think you have the label and value fields the wrong way around. Try something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;input type="dropdown" token="clientId" searchWhenChanged="true"&amp;gt;
&amp;lt;label&amp;gt;Integrator&amp;lt;/label&amp;gt;
&amp;lt;fieldForLabel&amp;gt;client&amp;lt;/fieldForLabel&amp;gt;
&amp;lt;fieldForValue&amp;gt;client_id&amp;lt;/fieldForValue&amp;gt;
&amp;lt;search&amp;gt;
&amp;lt;query&amp;gt;basic search | lookup clients client_id as client_id OUTPUTNEW client_name client_id
| eval client = client_name +"(" + client_id +")" | dedup client
| table client_id client&amp;lt;/query&amp;gt;
&amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
&amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
&amp;lt;/search&amp;gt;
&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;/input&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 14 Jan 2021 08:47:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Set-token-from-dropdown/m-p/535782#M151440</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-01-14T08:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: Set token from dropdown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Set-token-from-dropdown/m-p/535926#M151493</link>
      <description>&lt;P&gt;thanks for the reply,&lt;/P&gt;&lt;P&gt;I want dropdown in a same way -&amp;gt;client_name(client_id) ,example: Smith(123)&lt;/P&gt;&lt;P&gt;but&amp;nbsp; in a token I only want client_id(123) &lt;STRONG&gt;not&lt;/STRONG&gt; client_name(Smith), as I want to use in a panel query&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;row&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;chart&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;&amp;nbsp; Volume&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;Basic Search | search client_id="$clientId$" |eval URI1 = uri.....| timechart span="1m" count by URI1 usenull=f useother=f&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$time.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$time.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.chart"&amp;gt;line&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;/chart&amp;gt;&lt;BR /&gt;&amp;lt;/panel&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 00:10:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Set-token-from-dropdown/m-p/535926#M151493</guid>
      <dc:creator>smahuja</dc:creator>
      <dc:date>2021-01-15T00:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Set token from dropdown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Set-token-from-dropdown/m-p/535928#M151494</link>
      <description>&lt;P&gt;That's what this does.&lt;/P&gt;&lt;P&gt;fieldForValue is client_id (not client as you had in you original post). This is the value that the token clientId is set to when the user selects the option, and this is what you use in the panel query.&lt;/P&gt;&lt;P&gt;fieldForLabel is the composite string you constructed from the client name with the client_id in brackets. This is what is displayed in the dropdown.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;input type="dropdown" token="clientId" searchWhenChanged="true"&amp;gt;
&amp;lt;label&amp;gt;Integrator&amp;lt;/label&amp;gt;
&amp;lt;fieldForLabel&amp;gt;client&amp;lt;/fieldForLabel&amp;gt;
&amp;lt;fieldForValue&amp;gt;client_id&amp;lt;/fieldForValue&amp;gt;
&amp;lt;search&amp;gt;
&amp;lt;query&amp;gt;basic search | lookup clients client_id as client_id OUTPUTNEW client_name client_id
| eval client = client_name +"(" + client_id +")" | dedup client
| table client_id client&amp;lt;/query&amp;gt;
&amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
&amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
&amp;lt;/search&amp;gt;
&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;/input&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;How is this different to what you asked for?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 00:26:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Set-token-from-dropdown/m-p/535928#M151494</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-01-15T00:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Set token from dropdown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Set-token-from-dropdown/m-p/535930#M151496</link>
      <description>&lt;P&gt;Cool, Thanks..&lt;/P&gt;&lt;P&gt;Its working, sorry I misunderstood..&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 00:40:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Set-token-from-dropdown/m-p/535930#M151496</guid>
      <dc:creator>smahuja</dc:creator>
      <dc:date>2021-01-15T00:40:10Z</dc:date>
    </item>
  </channel>
</rss>

