<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkbox not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586631#M204339</link>
    <description>&lt;P&gt;Have you considered using the submit button? In order to use the submit button you have to change&amp;nbsp; "search on change" off on all your other inputs.&lt;BR /&gt;&lt;BR /&gt;-Marco&lt;/P&gt;</description>
    <pubDate>Fri, 25 Feb 2022 16:14:14 GMT</pubDate>
    <dc:creator>Marco_Develops</dc:creator>
    <dc:date>2022-02-25T16:14:14Z</dc:date>
    <item>
      <title>Why is checkbox not working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586614#M204335</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have created a dashboard to filter firewall statuses. One of the inputs I need is a checkbox to eliminate duplicates based on host, source IP, destination IP and destination port.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;However, the checkbox input is not working and every time the use checks and unchecks the box, it has no effect on the dashboard.&lt;BR /&gt;&lt;BR /&gt;The following is my dashboard and the XML code, respectively:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Checkbox Not Working UI.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18135iC4C2FA0E69B39D01/image-size/large?v=v2&amp;amp;px=999" role="button" title="Checkbox Not Working UI.PNG" alt="Checkbox Not Working UI.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Checkbox Not Working.PNG" style="width: 819px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18136i1C9630A09D6A9131/image-size/large?v=v2&amp;amp;px=999" role="button" title="Checkbox Not Working.PNG" alt="Checkbox Not Working.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Can you please help?&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 18:36:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586614#M204335</guid>
      <dc:creator>POR160893</dc:creator>
      <dc:date>2022-02-25T18:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: Checkbox not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586622#M204337</link>
      <description>&lt;P&gt;Please share the part of the dashboard code that uses the $checkboxDedup$ token.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 15:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586622#M204337</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-02-25T15:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Checkbox not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586626#M204338</link>
      <description>&lt;P&gt;At the moment, this token is not been used.&lt;BR /&gt;&lt;BR /&gt;I don't know how to incorporate it into one of my queries so that duplicates over 4 fields are detected.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;As you can see from the below code, I am already using the tokens from the other inputs in the base searches:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3 base queries.PNG" style="width: 653px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18137iF2C3B737813533DE/image-dimensions/653x628?v=v2" width="653" height="628" role="button" title="3 base queries.PNG" alt="3 base queries.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, for this checkbox, since I need to detect duplicates across source IP, dest IP, dest Port AND sourcetype, and I am already using a sourcetype token in my dropdown, I don't know how to make use make use of the 1 token in the checkbox when it would make sense to have 4 tokens ....... can you please help&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 15:39:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586626#M204338</guid>
      <dc:creator>POR160893</dc:creator>
      <dc:date>2022-02-25T15:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: Checkbox not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586631#M204339</link>
      <description>&lt;P&gt;Have you considered using the submit button? In order to use the submit button you have to change&amp;nbsp; "search on change" off on all your other inputs.&lt;BR /&gt;&lt;BR /&gt;-Marco&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 16:14:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586631#M204339</guid>
      <dc:creator>Marco_Develops</dc:creator>
      <dc:date>2022-02-25T16:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Checkbox not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586652#M204344</link>
      <description>&lt;P&gt;I think you only need one token, not 4 for dedup.&amp;nbsp; Just add the token between the &lt;FONT face="courier new,courier"&gt;table&lt;/FONT&gt; and first &lt;FONT face="courier new,courier"&gt;lookup&lt;/FONT&gt; commands.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| table ...
$checkboxDedup$
| lookup ...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 19:07:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586652#M204344</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-02-25T19:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Checkbox not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586748#M204377</link>
      <description>&lt;P&gt;When I added the dedup in between the table and lookup, the UI is now looking for some argument:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Dedup Not Working - UI.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18159iC5FF0D4B0921E55E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Dedup Not Working - UI.PNG" alt="Dedup Not Working - UI.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Dedup Not Working - Code.PNG" style="width: 988px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18160iC99C48DF5961EFE6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Dedup Not Working - Code.PNG" alt="Dedup Not Working - Code.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Can you&amp;nbsp; please help?&lt;/P&gt;</description>
      <pubDate>Sun, 27 Feb 2022 16:21:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586748#M204377</guid>
      <dc:creator>POR160893</dc:creator>
      <dc:date>2022-02-27T16:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: Checkbox not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586752#M204378</link>
      <description>&lt;P&gt;Since the token already contains a dedup command, saying &lt;FONT face="courier new,courier"&gt;| dedup $checkboxDedup$&lt;/FONT&gt; is equivalent to saying &lt;FONT face="courier new,courier"&gt;| dedup | dedup $sourcetype_tok$, $dest$, $src$, $port$&lt;/FONT&gt;.&lt;/P&gt;&lt;P&gt;Try the answer provided or change the token to not contain "&lt;FONT face="courier new,courier"&gt;| dedup&lt;/FONT&gt;"&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Feb 2022 18:50:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586752#M204378</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-02-27T18:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Checkbox not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586831#M204386</link>
      <description>&lt;P&gt;The submit button with the Dedup condition does work now .... but only on fields with the same name across both indexes. Here is the source query with the Dedup token been used:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Dedup Not Working - Code1.PNG" style="width: 836px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18167i97AAA1BDBBE91D09/image-size/large?v=v2&amp;amp;px=999" role="button" title="Dedup Not Working - Code1.PNG" alt="Dedup Not Working - Code1.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;However, I need to also have it check for dedup for src_ip and dest_ip. My issue is on the 2nd index, these two fields are called src and dest, respectively.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Dedup Not Working - Code2.PNG" style="width: 927px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18168i317AA3F80251D7AE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Dedup Not Working - Code2.PNG" alt="Dedup Not Working - Code2.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I tried using both names with an OR in the dedup but that did not work. Can you please help?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 12:03:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586831#M204386</guid>
      <dc:creator>POR160893</dc:creator>
      <dc:date>2022-02-28T12:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: Checkbox not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586832#M204387</link>
      <description>&lt;P&gt;Hey, The submit button with the Dedup condition does work now .... but only on fields with the same name across both indexes. Here is the source query with the Dedup token been used:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Dedup Not Working - Code1.PNG" style="width: 836px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18167i97AAA1BDBBE91D09/image-size/large?v=v2&amp;amp;px=999" role="button" title="Dedup Not Working - Code1.PNG" alt="Dedup Not Working - Code1.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;However, I need to also have it check for dedup for src_ip and dest_ip. My issue is on the 2nd index, these two fields are called src and dest, respectively.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Dedup Not Working - Code2.PNG" style="width: 927px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18168i317AA3F80251D7AE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Dedup Not Working - Code2.PNG" alt="Dedup Not Working - Code2.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I tried using both names with an OR in the dedup but that did not work. Can you please help?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 12:04:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586832#M204387</guid>
      <dc:creator>POR160893</dc:creator>
      <dc:date>2022-02-28T12:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Checkbox not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586863#M204399</link>
      <description>&lt;P&gt;The dedup command does not accept expressions - only field names.&amp;nbsp; You'll probably need to normalize the field names using &lt;FONT face="courier new,courier"&gt;rename&lt;/FONT&gt; or &lt;FONT face="courier new,courier"&gt;coalesce&lt;/FONT&gt; (or other method) for dedup to work as expected.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 15:30:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/586863#M204399</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-02-28T15:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Checkbox not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/665633#M228371</link>
      <description>&lt;P&gt;I've had the exact same use case and found a work around. Added this just in case anyone else stumbles across it.&lt;BR /&gt;&lt;BR /&gt;Update the default option to noop, so it reverts to this when the checkbox is deselected&lt;BR /&gt;&amp;lt;input type="checkbox" token="dedupresults"&amp;gt;&lt;BR /&gt;&amp;lt;choice value="dedup src,dest"&amp;gt;Dedup&amp;lt;/choice&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;noop&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;/P&gt;&lt;P&gt;And insert the token into your search.&amp;nbsp;&lt;BR /&gt;.... | $dedupresults$ | .....&lt;/P&gt;&lt;P&gt;This will result in the search being either&lt;/P&gt;&lt;P&gt;... |&amp;nbsp;dedup src,dest | .....&amp;nbsp; or&amp;nbsp;... |&amp;nbsp;noop | .....&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 03:46:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-checkbox-not-working/m-p/665633#M228371</guid>
      <dc:creator>schalb</dc:creator>
      <dc:date>2023-10-20T03:46:42Z</dc:date>
    </item>
  </channel>
</rss>

