<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is the best solution to table list of keys which can be eventually used for input dropdown in dashboard? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-best-solution-to-table-list-of-keys-which-can-be/m-p/609838#M212068</link>
    <description>&lt;P&gt;Hello Folks ,&lt;/P&gt;
&lt;P&gt;I have json data in below format. I am looking for a best solution to table list of Keys which can be eventually used for input dropdown in dashboard.&lt;/P&gt;
&lt;P&gt;output of the table content needs to be like below. your help is much appreciated.&lt;/P&gt;
&lt;P&gt;bzk.f1&lt;/P&gt;
&lt;P&gt;bzk.f4&lt;/P&gt;
&lt;P&gt;bzk.f8&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="http://czcholstc002045.prg-dc.dhl.com:8000/en-US/app/GCASIT2/search?q=search%20index%3D%22gca_sit_logs%22%20sourcetype%3D%22gca_log_json%22%20source%3D%22http%3Agca_sit_hec_log%22%20%22hdr.c%22%3D%22GCAGetSDFE%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=%40d&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1660750726.3886#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;bzk&lt;/SPAN&gt;:&amp;nbsp;{&amp;nbsp;&lt;A class="" href="http://czcholstc002045.prg-dc.dhl.com:8000/en-US/app/GCASIT2/search?q=search%20index%3D%22gca_sit_logs%22%20sourcetype%3D%22gca_log_json%22%20source%3D%22http%3Agca_sit_hec_log%22%20%22hdr.c%22%3D%22GCAGetSDFE%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=%40d&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1660750726.3886#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;f1&lt;/SPAN&gt;: &lt;SPAN class=""&gt;ABC&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;f4&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;ABC&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;f8&lt;/SPAN&gt;: &lt;SPAN class=""&gt;ABC&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Aug 2022 16:53:16 GMT</pubDate>
    <dc:creator>kirangurram</dc:creator>
    <dc:date>2022-08-17T16:53:16Z</dc:date>
    <item>
      <title>What is the best solution to table list of keys which can be eventually used for input dropdown in dashboard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-best-solution-to-table-list-of-keys-which-can-be/m-p/609838#M212068</link>
      <description>&lt;P&gt;Hello Folks ,&lt;/P&gt;
&lt;P&gt;I have json data in below format. I am looking for a best solution to table list of Keys which can be eventually used for input dropdown in dashboard.&lt;/P&gt;
&lt;P&gt;output of the table content needs to be like below. your help is much appreciated.&lt;/P&gt;
&lt;P&gt;bzk.f1&lt;/P&gt;
&lt;P&gt;bzk.f4&lt;/P&gt;
&lt;P&gt;bzk.f8&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="http://czcholstc002045.prg-dc.dhl.com:8000/en-US/app/GCASIT2/search?q=search%20index%3D%22gca_sit_logs%22%20sourcetype%3D%22gca_log_json%22%20source%3D%22http%3Agca_sit_hec_log%22%20%22hdr.c%22%3D%22GCAGetSDFE%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=%40d&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1660750726.3886#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;bzk&lt;/SPAN&gt;:&amp;nbsp;{&amp;nbsp;&lt;A class="" href="http://czcholstc002045.prg-dc.dhl.com:8000/en-US/app/GCASIT2/search?q=search%20index%3D%22gca_sit_logs%22%20sourcetype%3D%22gca_log_json%22%20source%3D%22http%3Agca_sit_hec_log%22%20%22hdr.c%22%3D%22GCAGetSDFE%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=%40d&amp;amp;latest=now&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1660750726.3886#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;f1&lt;/SPAN&gt;: &lt;SPAN class=""&gt;ABC&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;f4&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;ABC&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;f8&lt;/SPAN&gt;: &lt;SPAN class=""&gt;ABC&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 16:53:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-best-solution-to-table-list-of-keys-which-can-be/m-p/609838#M212068</guid>
      <dc:creator>kirangurram</dc:creator>
      <dc:date>2022-08-17T16:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best solution to table list of keys which can be eventually used for input dropdown in dashboard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-best-solution-to-table-list-of-keys-which-can-be/m-p/609841#M212070</link>
      <description>&lt;LI-CODE lang="markup"&gt;| spath
| fields - _time _raw
| transpose column_name=name
| fields name&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 17 Aug 2022 16:55:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-best-solution-to-table-list-of-keys-which-can-be/m-p/609841#M212070</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-08-17T16:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best solution to table list of keys which can be eventually used for input dropdown in dashboard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-best-solution-to-table-list-of-keys-which-can-be/m-p/609939#M212098</link>
      <description>&lt;P&gt;So, your data already contain fields named bzk.f1, bzk.f4, etc. &amp;nbsp;The following should give you a single-field table:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| foreach bzk.*
    [eval inputfield = mvappend(inputfield, "&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;")]
| table inputfield&lt;/LI-CODE&gt;&lt;P&gt;Alternatively, you can use spath together with the newer JSON functions&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath input=data path=bzk
| eval inputfield = json_array_to_mv(json_keys(bzk))
| eval inputfield = mvmap(inputfield, "bzk." . inputfield)
| table inputfield&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 09:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-best-solution-to-table-list-of-keys-which-can-be/m-p/609939#M212098</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-08-18T09:03:17Z</dc:date>
    </item>
  </channel>
</rss>

