<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dashboard token value substitution in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-token-value-substitution/m-p/563978#M196452</link>
    <description>&lt;P&gt;Edited after I learned to read:&lt;/P&gt;&lt;P&gt;You should be able to use the replace function for this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where customer="foo" AND like(Register,replace("$tok_reg_num$", "\*", "%"))&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Original Reply:&lt;/P&gt;&lt;P&gt;Try using &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/ConditionalFunctions#searchmatch.28X.29" target="_self"&gt;searchmatch&lt;/A&gt; in your where statement. &amp;nbsp;It will take a regular SPL search statement and is compatible with the asterisk as the wild card.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where customer="foo" AND searchmatch("Register=\"$tok_reg_num$\"")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Aug 2021 16:41:16 GMT</pubDate>
    <dc:creator>justinatpnnl</dc:creator>
    <dc:date>2021-08-19T16:41:16Z</dc:date>
    <item>
      <title>Dashboard token value substitution</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-token-value-substitution/m-p/563974#M196451</link>
      <description>&lt;P&gt;Hi&amp;nbsp; I have a input token in my dashboard for register number called&lt;STRONG&gt; $tok_reg_num$.&lt;/STRONG&gt;&lt;BR /&gt;The customers can put in a specific number or leave it as the default of "*".&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Here's the issue,&amp;nbsp; in one of the dashboard searches I can use the default of "*"&amp;nbsp; &amp;nbsp;(e..g&amp;nbsp; &lt;EM&gt;index=blah sourcetype=blahblah register_number=*&lt;/EM&gt;),&amp;nbsp; in a secondary panel&amp;nbsp; I have to use a where&amp;nbsp; with a LIKE clause due to the different log type to filter the register number so * won't work and I need to change it to a&amp;nbsp; %.&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Non-working:&lt;BR /&gt;&lt;EM&gt;| Where customer="foo" AND like(Register,"*")&amp;nbsp; &amp;lt;--the&amp;nbsp; dashboard default for&amp;nbsp; $tok_reg_num$&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;I want it to be this:&lt;BR /&gt;&lt;EM&gt;| Where customer="foo" AND like(Register,"%")&amp;nbsp; &amp;lt;- change the $tok_reg_num$ to %&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;I have exhausted my meager splunk token experience in trying to get this to work.&amp;nbsp;&lt;BR /&gt;I can't figure out if I can examine and change it in the search&amp;nbsp; or do I need to do that&amp;nbsp; on the dashboard.&amp;nbsp; &amp;nbsp;Someone give me a nudge in the right direction, please&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 16:17:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-token-value-substitution/m-p/563974#M196451</guid>
      <dc:creator>randy_moore</dc:creator>
      <dc:date>2021-08-19T16:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard token value substitution</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-token-value-substitution/m-p/563978#M196452</link>
      <description>&lt;P&gt;Edited after I learned to read:&lt;/P&gt;&lt;P&gt;You should be able to use the replace function for this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where customer="foo" AND like(Register,replace("$tok_reg_num$", "\*", "%"))&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Original Reply:&lt;/P&gt;&lt;P&gt;Try using &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/ConditionalFunctions#searchmatch.28X.29" target="_self"&gt;searchmatch&lt;/A&gt; in your where statement. &amp;nbsp;It will take a regular SPL search statement and is compatible with the asterisk as the wild card.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where customer="foo" AND searchmatch("Register=\"$tok_reg_num$\"")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 16:41:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-token-value-substitution/m-p/563978#M196452</guid>
      <dc:creator>justinatpnnl</dc:creator>
      <dc:date>2021-08-19T16:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard token value substitution</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-token-value-substitution/m-p/563982#M196453</link>
      <description>&lt;P class="lia-align-justify"&gt;Replace was the trick&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/74458"&gt;@justinatpnnl&lt;/a&gt;&amp;nbsp;.&amp;nbsp; &amp;nbsp; Worked perfectly.&amp;nbsp; &amp;nbsp;Many many thanks!&lt;BR /&gt;&lt;BR /&gt;Randy&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 17:47:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-token-value-substitution/m-p/563982#M196453</guid>
      <dc:creator>randy_moore</dc:creator>
      <dc:date>2021-08-19T17:47:33Z</dc:date>
    </item>
  </channel>
</rss>

