<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using different input lookup commands based on token given in a dropdown in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Using-different-input-lookup-commands-based-on-token-given-in-a/m-p/555381#M157648</link>
    <description>&lt;P&gt;You can do that.&amp;nbsp;&lt;BR /&gt;In environment dropdown,&amp;nbsp;&lt;SPAN&gt;field1Value and&amp;nbsp;field2Value should be your lookup names. Then in company dropdown use&amp;nbsp; that token in place of lookup name in inputlookup command&lt;BR /&gt;&lt;BR /&gt;In&amp;nbsp;environment dropdown&lt;BR /&gt;field1 lookup1.csv&lt;BR /&gt;field2 lookup2.csv&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In company dropdown&lt;BR /&gt;| inputlookup $tokenfromenvironment$&lt;BR /&gt;| fields description, value&lt;BR /&gt;| dedup description, value&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jun 2021 20:34:12 GMT</pubDate>
    <dc:creator>rupkumar4sec</dc:creator>
    <dc:date>2021-06-10T20:34:12Z</dc:date>
    <item>
      <title>Using different input lookup commands based on token given in a dropdown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-different-input-lookup-commands-based-on-token-given-in-a/m-p/555380#M157647</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;First time poster, new to Splunk and query languages in general, please forgive if this is a silly question.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am trying to insert an additional layer of tokenization into a chained series of dropdowns. Working for my dashboard is a dropdown that gives us a set of values based on an input lookup command:&lt;BR /&gt;&lt;BR /&gt;company dropdown ( input lookup xxxxx.csv) -&amp;gt; token2 dropdown-&amp;gt; token3 dropdown etc..&lt;BR /&gt;&lt;BR /&gt;The ideal situation is using a new 'environment' dropdown that will pass it's token to the company dropdown to segregate the items listed in 'company' based on environment. I have two lookup files, each containing the relevant key/value pairings of that environment. Is it possible to use a token to change a search entirely based on what token is received?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In more detail:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Company dropdown search:&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;| inputlookup xxxxxxx.csv&lt;BR /&gt;| fields description, value&lt;BR /&gt;| dedup description, value&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;The format of the lookup tables:&lt;/STRONG&gt;&lt;BR /&gt;2 rows:&lt;BR /&gt;value description&lt;BR /&gt;value1 description1&lt;BR /&gt;value2 description2&lt;BR /&gt;etc...&lt;BR /&gt;&lt;BR /&gt;Environment has two static values (field1, field1Value), (field2, field2Value). Can I pass in a different lookup table (or, just pass in a similar search with a different lookup) to the company dropdown, based on what environment token is given?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It's not lost on me that I may be going about this the wrong way. If I'm going totally the wrong direction, let me know.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 20:20:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-different-input-lookup-commands-based-on-token-given-in-a/m-p/555380#M157647</guid>
      <dc:creator>ft_kd02</dc:creator>
      <dc:date>2021-06-10T20:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: Using different input lookup commands based on token given in a dropdown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-different-input-lookup-commands-based-on-token-given-in-a/m-p/555381#M157648</link>
      <description>&lt;P&gt;You can do that.&amp;nbsp;&lt;BR /&gt;In environment dropdown,&amp;nbsp;&lt;SPAN&gt;field1Value and&amp;nbsp;field2Value should be your lookup names. Then in company dropdown use&amp;nbsp; that token in place of lookup name in inputlookup command&lt;BR /&gt;&lt;BR /&gt;In&amp;nbsp;environment dropdown&lt;BR /&gt;field1 lookup1.csv&lt;BR /&gt;field2 lookup2.csv&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In company dropdown&lt;BR /&gt;| inputlookup $tokenfromenvironment$&lt;BR /&gt;| fields description, value&lt;BR /&gt;| dedup description, value&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 20:34:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-different-input-lookup-commands-based-on-token-given-in-a/m-p/555381#M157648</guid>
      <dc:creator>rupkumar4sec</dc:creator>
      <dc:date>2021-06-10T20:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Using different input lookup commands based on token given in a dropdown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-different-input-lookup-commands-based-on-token-given-in-a/m-p/555384#M157651</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/91548"&gt;@rupkumar4sec&lt;/a&gt; Thank you, so simple!&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 21:04:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-different-input-lookup-commands-based-on-token-given-in-a/m-p/555384#M157651</guid>
      <dc:creator>ft_kd02</dc:creator>
      <dc:date>2021-06-10T21:04:17Z</dc:date>
    </item>
  </channel>
</rss>

