<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Condition statements for seach query based on Token in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611537#M212618</link>
    <description>&lt;P&gt;Yes, Simple XML has a &amp;lt;condition /&amp;gt; element, see&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#condition_.28form_input.29" target="_blank" rel="noopener"&gt;condition (form input)&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#condition_.28drilldown.29" target="_blank" rel="noopener"&gt;condition (drilldown)&lt;/A&gt;, as well as&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#change_.28form_input.29" target="_blank" rel="noopener"&gt;change (form input)&lt;/A&gt;. &amp;nbsp;But &amp;lt;condition /&amp;gt; can also be used inside &amp;lt;search /&amp;gt; directly, which is what you want to use. &amp;nbsp;The idea is to set visual elements based on that token's initial value.&lt;/P&gt;&lt;P&gt;Here is a dummy dashboard to play with.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;Set token on load&amp;lt;/label&amp;gt;
  &amp;lt;!-- init&amp;gt;
    &amp;lt;set token="master_token"&amp;gt;Data Entry&amp;lt;/set&amp;gt;
  &amp;lt;/init --&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;
    &amp;lt;input type="dropdown" token="master_token" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;master token&amp;lt;/label&amp;gt;
      &amp;lt;choice value="Data Entry"&amp;gt;Data entry&amp;lt;/choice&amp;gt;
      &amp;lt;choice value="Click Only"&amp;gt;Click only&amp;lt;/choice&amp;gt;
      &amp;lt;choice value="Attachment"&amp;gt;Attachment&amp;lt;/choice&amp;gt;
      &amp;lt;default&amp;gt;Data Entry&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;search&amp;gt;
    &amp;lt;query&amp;gt;
      | makeresults
      | fields - _time
      | eval master_token="$master_token$"
    &amp;lt;/query&amp;gt;
    &amp;lt;progress&amp;gt;
      &amp;lt;condition match="master_token==&amp;amp;quot;Data Entry&amp;amp;quot;"&amp;gt;
        &amp;lt;set token="data_entry"&amp;gt;True&amp;lt;/set&amp;gt;
        &amp;lt;unset token="attachment"&amp;gt;&amp;lt;/unset&amp;gt;
        &amp;lt;unset token="click_only"&amp;gt;&amp;lt;/unset&amp;gt;
      &amp;lt;/condition&amp;gt;
      &amp;lt;condition match="master_token==&amp;amp;quot;Click Only&amp;amp;quot;"&amp;gt;
        &amp;lt;set token="click_only"&amp;gt;True&amp;lt;/set&amp;gt;
        &amp;lt;unset token="data_entry"&amp;gt;&amp;lt;/unset&amp;gt;
        &amp;lt;unset token="attachment"&amp;gt;&amp;lt;/unset&amp;gt;
      &amp;lt;/condition&amp;gt;
      &amp;lt;condition match="master_token==&amp;amp;quot;Attachment&amp;amp;quot;"&amp;gt;
        &amp;lt;set token="attachment"&amp;gt;True&amp;lt;/set&amp;gt;
        &amp;lt;unset token="click_only"&amp;gt;&amp;lt;/unset&amp;gt;
        &amp;lt;unset token="data_entry"&amp;gt;&amp;lt;/unset&amp;gt;
      &amp;lt;/condition&amp;gt;
    &amp;lt;/progress&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;html&amp;gt;
        &amp;lt;div&amp;gt;master_token: $master_token$&amp;lt;/div&amp;gt;
        &amp;lt;div&amp;gt;data_entry: $data_entry$&amp;lt;/div&amp;gt;
        &amp;lt;div&amp;gt;click_only: $click_only$&amp;lt;/div&amp;gt;
        &amp;lt;div&amp;gt;attachment: $attachment$&amp;lt;/div&amp;gt;
      &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;Once you set this up, you can play with it by supplying master_token in the URL, e.g.,&amp;nbsp;&lt;A title="test dashboard" href="http://localhost:8000/en-US/app/search/set_token_on_load?master_token=Data%20Entry" target="_blank" rel="noopener"&gt;http://localhost:8000/en-US/app/search/set_token_on_load?master_token=Data%20Entry&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Sep 2022 05:35:29 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2022-09-01T05:35:29Z</dc:date>
    <item>
      <title>Which Condition Function for | seach  based on Token should I use?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611534#M212616</link>
      <description>&lt;P&gt;Case Scenario:&lt;/P&gt;
&lt;P&gt;Dashboard A is clicked, thus sending a token whose value is hostname ($hostnameToken$) to Dashboard B. &lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Dashboard B with the following query has received $hostnameToken$ , then used on | search host_name , when search | search query returns “Results not Found”&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; index=S score&amp;gt;=7.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | lookup A.csv IP Address as ip OUTPUTNEW Squad&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | lookup B.csv IP as ip OUTPUTNEW PIC, Email&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | lookup C.csv ip as ip OUTPUTNEW host_name&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IF&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (true)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | search host_name="$hostnameToken$"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; THEN DO THIS:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; | stats values(plugin) as Plugin values(solution) as Solution values(PIC) as pic values(Email) as email&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; values(Squad) as squad by ip&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ELSE&amp;nbsp;&amp;nbsp; (false)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | eval hostToken="$hostnameToken$"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; | lookup CortexHostIp2.csv host_name as hostToken OUTPUTNEW ip&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | search ip=ip&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; THEN DO THIS:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; | stats values(plugin) as Plugin values(solution) as Solution values(PIC) as pic values(Email)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; as email values(Squad) as squad by ip&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The next search is carried out by converting the hostname token value to IP via eval and lookup. If both ELSE conditions are not met (value is False), then the search stops.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How to implement conditional statements into the above query? What is the right query to use?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 14:48:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611534#M212616</guid>
      <dc:creator>time2200</dc:creator>
      <dc:date>2022-09-01T14:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Condition statements for seach query based on Token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611537#M212618</link>
      <description>&lt;P&gt;Yes, Simple XML has a &amp;lt;condition /&amp;gt; element, see&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#condition_.28form_input.29" target="_blank" rel="noopener"&gt;condition (form input)&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#condition_.28drilldown.29" target="_blank" rel="noopener"&gt;condition (drilldown)&lt;/A&gt;, as well as&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#change_.28form_input.29" target="_blank" rel="noopener"&gt;change (form input)&lt;/A&gt;. &amp;nbsp;But &amp;lt;condition /&amp;gt; can also be used inside &amp;lt;search /&amp;gt; directly, which is what you want to use. &amp;nbsp;The idea is to set visual elements based on that token's initial value.&lt;/P&gt;&lt;P&gt;Here is a dummy dashboard to play with.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;Set token on load&amp;lt;/label&amp;gt;
  &amp;lt;!-- init&amp;gt;
    &amp;lt;set token="master_token"&amp;gt;Data Entry&amp;lt;/set&amp;gt;
  &amp;lt;/init --&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;
    &amp;lt;input type="dropdown" token="master_token" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;master token&amp;lt;/label&amp;gt;
      &amp;lt;choice value="Data Entry"&amp;gt;Data entry&amp;lt;/choice&amp;gt;
      &amp;lt;choice value="Click Only"&amp;gt;Click only&amp;lt;/choice&amp;gt;
      &amp;lt;choice value="Attachment"&amp;gt;Attachment&amp;lt;/choice&amp;gt;
      &amp;lt;default&amp;gt;Data Entry&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;search&amp;gt;
    &amp;lt;query&amp;gt;
      | makeresults
      | fields - _time
      | eval master_token="$master_token$"
    &amp;lt;/query&amp;gt;
    &amp;lt;progress&amp;gt;
      &amp;lt;condition match="master_token==&amp;amp;quot;Data Entry&amp;amp;quot;"&amp;gt;
        &amp;lt;set token="data_entry"&amp;gt;True&amp;lt;/set&amp;gt;
        &amp;lt;unset token="attachment"&amp;gt;&amp;lt;/unset&amp;gt;
        &amp;lt;unset token="click_only"&amp;gt;&amp;lt;/unset&amp;gt;
      &amp;lt;/condition&amp;gt;
      &amp;lt;condition match="master_token==&amp;amp;quot;Click Only&amp;amp;quot;"&amp;gt;
        &amp;lt;set token="click_only"&amp;gt;True&amp;lt;/set&amp;gt;
        &amp;lt;unset token="data_entry"&amp;gt;&amp;lt;/unset&amp;gt;
        &amp;lt;unset token="attachment"&amp;gt;&amp;lt;/unset&amp;gt;
      &amp;lt;/condition&amp;gt;
      &amp;lt;condition match="master_token==&amp;amp;quot;Attachment&amp;amp;quot;"&amp;gt;
        &amp;lt;set token="attachment"&amp;gt;True&amp;lt;/set&amp;gt;
        &amp;lt;unset token="click_only"&amp;gt;&amp;lt;/unset&amp;gt;
        &amp;lt;unset token="data_entry"&amp;gt;&amp;lt;/unset&amp;gt;
      &amp;lt;/condition&amp;gt;
    &amp;lt;/progress&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;html&amp;gt;
        &amp;lt;div&amp;gt;master_token: $master_token$&amp;lt;/div&amp;gt;
        &amp;lt;div&amp;gt;data_entry: $data_entry$&amp;lt;/div&amp;gt;
        &amp;lt;div&amp;gt;click_only: $click_only$&amp;lt;/div&amp;gt;
        &amp;lt;div&amp;gt;attachment: $attachment$&amp;lt;/div&amp;gt;
      &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;Once you set this up, you can play with it by supplying master_token in the URL, e.g.,&amp;nbsp;&lt;A title="test dashboard" href="http://localhost:8000/en-US/app/search/set_token_on_load?master_token=Data%20Entry" target="_blank" rel="noopener"&gt;http://localhost:8000/en-US/app/search/set_token_on_load?master_token=Data%20Entry&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 05:35:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611537#M212618</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-09-01T05:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Condition statements for seach query based on Token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611540#M212619</link>
      <description>&lt;P&gt;How to implement | eval to query on the above, or any condition query?&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/If-else-conditional-statements-for-search/m-p/104919#M27197" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/If-else-conditional-statements-for-search/m-p/104919#M27197&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 06:22:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611540#M212619</guid>
      <dc:creator>time2200</dc:creator>
      <dc:date>2022-09-01T06:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: Condition statements for seach query based on Token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611543#M212621</link>
      <description>&lt;P&gt;thanks for responding this my post bro,&lt;BR /&gt;but what i mean is a fundamental change in query level, for its logic, without changing the XML.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 06:37:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611543#M212621</guid>
      <dc:creator>time2200</dc:creator>
      <dc:date>2022-09-01T06:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Condition Function for | seach  based on Token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611546#M212623</link>
      <description>&lt;P&gt;index=S score&amp;gt;=7.0&lt;BR /&gt;| lookup A.csv IP Address as ip OUTPUTNEW Squad&lt;BR /&gt;| lookup B.csv IP as ip OUTPUTNEW PIC, Email&lt;BR /&gt;| lookup C.csv ip as ip OUTPUTNEW host_name&lt;BR /&gt;| search host_name="$hostnameToken$" OR | search host_name=""&lt;BR /&gt;| eval hostToken="$hostnameToken$"&lt;BR /&gt;| lookup CortexHostIp2.csv host_name as hostToken OUTPUTNEW ip&lt;BR /&gt;| search ip=ip&lt;BR /&gt;| stats values(plugin) as Plugin values(solution) as Solution values(PIC) as pic values(Email) as emailvalues(Squad) as squad by ip&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 07:04:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611546#M212623</guid>
      <dc:creator>time2200</dc:creator>
      <dc:date>2022-09-01T07:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Condition Function for | seach  based on Token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611594#M212628</link>
      <description>&lt;P&gt;this query isnt work, need any input from user in splunk community.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 11:23:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611594#M212628</guid>
      <dc:creator>time2200</dc:creator>
      <dc:date>2022-09-01T11:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Condition statements for seach query based on Token</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611599#M212630</link>
      <description>&lt;P&gt;But changing Simple XML is perhaps the least complex solution, if there is an alternative one. &amp;nbsp;In fact, after reexamine your description, dashboard B probably does not need conditional token setting. &amp;nbsp;Instead, you need to separate panels to handle the two conditions, because your base search, i.e.,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;        index=S score&amp;gt;=7.0
        | lookup A.csv IP Address as ip OUTPUTNEW Squad
        | lookup B.csv IP as ip OUTPUTNEW PIC, Email
        | lookup C.csv ip as ip OUTPUTNEW host_name&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;generally returns some events matching &lt;SPAN&gt;host_name="$hostnameToken$", some not.&lt;/SPAN&gt;&amp;nbsp; (If this is not true, you can go back to setting dynamic panels.) &amp;nbsp;You need two panels in order to show all conditions.&lt;/P&gt;&lt;P&gt;Consider this emulated dashboard:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;Search based on token&amp;lt;/label&amp;gt;
  &amp;lt;description&amp;gt;https://community.splunk.com/t5/Splunk-Search/Condition-Function-for-seach-based-on-Token/&amp;lt;/description&amp;gt;
  &amp;lt;init&amp;gt;
    &amp;lt;!-- set token="hostnameToken"&amp;gt;host1&amp;lt;/set --&amp;gt;
  &amp;lt;/init&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;hostnameToken=$hostnameToken$&amp;lt;/title&amp;gt;
      &amp;lt;html&amp;gt;
        &amp;lt;head&amp;gt;
          &amp;lt;style&amp;gt;
          table, th, td {
            border: 1px solid black;
          }
          &amp;lt;/style&amp;gt;
        &amp;lt;/head&amp;gt;
        &amp;lt;body&amp;gt;
          &amp;lt;p&amp;gt;Base search
            &amp;lt;pre&amp;gt;
index=S score&amp;amp;gt;=7.0
| lookup A.csv IP Address as ip OUTPUTNEW Squad
| lookup B.csv IP as ip OUTPUTNEW PIC, Email
| lookup C.csv ip as ip OUTPUTNEW host_name
            &amp;lt;/pre&amp;gt;
          &amp;lt;/p&amp;gt;
          &amp;lt;p&amp;gt;
            Emulated output from (no filter)
          &amp;lt;/p&amp;gt;
          &amp;lt;table&amp;gt;
            &amp;lt;tr&amp;gt;
              &amp;lt;th&amp;gt;Email&amp;lt;/th&amp;gt;	&amp;lt;th&amp;gt;PIC&amp;lt;/th&amp;gt;	&amp;lt;th&amp;gt;Squad&amp;lt;/th&amp;gt;	&amp;lt;th&amp;gt;host_name&amp;lt;/th&amp;gt;	&amp;lt;th&amp;gt;ip&amp;lt;/th&amp;gt;	&amp;lt;th&amp;gt;plugin&amp;lt;/th&amp;gt;	&amp;lt;th&amp;gt;solution&amp;lt;/th&amp;gt;
            &amp;lt;/tr&amp;gt;
            &amp;lt;tr&amp;gt;
              &amp;lt;td&amp;gt;email1@fake.com&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;somePIC&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;Squad1&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;host1&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;192.168.1.11&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;PluginA&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;somesolutionB&amp;lt;/td&amp;gt;
            &amp;lt;/tr&amp;gt;
            &amp;lt;tr&amp;gt;
              &amp;lt;td&amp;gt;email2@fake.com&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;somePIC&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;Squad1&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;host2&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;192.168.1.12&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;PluginA&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;somesolution2&amp;lt;/td&amp;gt;
            &amp;lt;/tr&amp;gt;
            &amp;lt;tr&amp;gt;
              &amp;lt;td&amp;gt;email3@fake.com&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;somePIC2&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;SquadB&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;host1&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;192.168.1.11&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;PluginB&amp;lt;/td&amp;gt;	&amp;lt;td&amp;gt;someslutionB&amp;lt;/td&amp;gt;
            &amp;lt;/tr&amp;gt;
          &amp;lt;/table&amp;gt;
        &amp;lt;/body&amp;gt;
      &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;search host_name = $hostnameToken$&amp;lt;/title&amp;gt;
      &amp;lt;html&amp;gt;
        &amp;lt;pre&amp;gt;
index=S score&amp;amp;gt;=7.0
| lookup A.csv IP Address as ip OUTPUTNEW Squad
| lookup B.csv IP as ip OUTPUTNEW PIC, Email
| lookup C.csv ip as ip OUTPUTNEW host_name
| search host_name = &amp;amp;#36;hostnameToken&amp;amp;#36;
| stats values(plugin) as Plugin values(solution) as Solution values(PIC) as pic values(Email) as email values(Squad) as squad by ip
        &amp;lt;/pre&amp;gt;
        &amp;lt;p&amp;gt;renders into&amp;lt;/p&amp;gt;
        &amp;lt;pre&amp;gt;
index=S score&amp;amp;gt;=7.0
| lookup A.csv IP Address as ip OUTPUTNEW Squad
| lookup B.csv IP as ip OUTPUTNEW PIC, Email
| lookup C.csv ip as ip OUTPUTNEW host_name
| search host_name = $hostnameToken$
| stats values(plugin) as Plugin values(solution) as Solution values(PIC) as pic values(Email) as email values(Squad) as squad by ip
        &amp;lt;/pre&amp;gt;
        &amp;lt;p&amp;gt;Emulated output:&amp;lt;/p&amp;gt;
      &amp;lt;/html&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| makeresults
| eval _raw = "dummy,host_name,ip,plugin,solution,PIC,Email,Squad
,host1,192.168.1.11,PluginA,somesolutionB,somePIC,email1@fake.com,Squad1
,host2,192.168.1.12,PluginA,somesolution2,somePIC,email2@fake.com,Squad1
,host1,192.168.1.11,PluginB,someslutionB,somePIC2,email3@fake.com,SquadB"
| multikv forceheader=1
``` the above emulates
        index=S score&amp;amp;gt;=7.0
        | lookup A.csv IP Address as ip OUTPUTNEW Squad
        | lookup B.csv IP as ip OUTPUTNEW PIC, Email
        | lookup C.csv ip as ip OUTPUTNEW host_name
```
| search host_name="$hostnameToken$"
| stats values(plugin) as Plugin values(solution) as Solution values(PIC) as pic values(Email) as email values(Squad) as squad by ip&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;search host_name != $hostnameToken$&amp;lt;/title&amp;gt;
      &amp;lt;html&amp;gt;
        &amp;lt;p&amp;gt;Run your second search here.  For example,&amp;lt;/p&amp;gt;
        &amp;lt;pre&amp;gt;
index=S score&amp;gt;=7.0
| lookup A.csv IP Address as ip OUTPUTNEW Squad
| lookup B.csv IP as ip OUTPUTNEW PIC, Email
| lookup C.csv ip as ip OUTPUTNEW host_name
| search host_name="&amp;amp;#36;hostnameToken&amp;amp;#36;" OR | search host_name=""
| eval hostToken="&amp;amp;#36;hostnameToken&amp;amp;#36;"
| lookup CortexHostIp2.csv host_name as hostToken OUTPUTNEW ip
| search ip=ip ``` what is the use of alway-true search? ```
| stats values(plugin) as Plugin values(solution) as Solution values(PIC) as pic values(Email) as emailvalues(Squad) as squad by ip
        &amp;lt;/pre&amp;gt;
        &amp;lt;p&amp;gt;
          which renders into
        &amp;lt;/p&amp;gt;
        &amp;lt;pre&amp;gt;
index=S score&amp;gt;=7.0
| lookup A.csv IP Address as ip OUTPUTNEW Squad
| lookup B.csv IP as ip OUTPUTNEW PIC, Email
| lookup C.csv ip as ip OUTPUTNEW host_name
| search host_name="$hostnameToken$" OR | search host_name=""
| eval hostToken="$hostnameToken$"
| lookup CortexHostIp2.csv host_name as hostToken OUTPUTNEW ip
| search ip=ip ``` what is the use of alway-true search? ```
| stats values(plugin) as Plugin values(solution) as Solution values(PIC) as pic values(Email) as emailvalues(Squad) as squad by ip
        &amp;lt;/pre&amp;gt;
      &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;If you query&amp;nbsp;&lt;A href="http://localhost:8000/en-US/app/search/search_based_on_token?hostnameToken=host1," target="_blank" rel="noopener"&gt;http://localhost:8000/en-US/app/search/search_based_on_token?hostnameToken=host1,&lt;/A&gt;&amp;nbsp;the left-hand panel (IF&lt;SPAN&gt; host_name="$hostnameToken$")&lt;/SPAN&gt;&amp;nbsp;shows&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;ip&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;Plugin&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;Solution&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;pic&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;email&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;squad&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;192.168.1.11&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;PluginA&lt;/DIV&gt;&lt;DIV class=""&gt;PluginB&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;someslutionB&lt;/DIV&gt;&lt;DIV class=""&gt;somesolutionB&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;somePIC&lt;/DIV&gt;&lt;DIV class=""&gt;somePIC2&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;email1@fake.com&lt;/DIV&gt;&lt;DIV class=""&gt;email3@fake.com&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;Squad1&lt;/DIV&gt;&lt;DIV class=""&gt;SquadB&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;But if you query&amp;nbsp;&lt;A href="http://localhost:8000/en-US/app/search/search_based_on_token?hostnameToken=host2," target="_blank" rel="noopener"&gt;http://localhost:8000/en-US/app/search/search_based_on_token?hostnameToken=host2,&lt;/A&gt;&amp;nbsp;it shows&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;ip&lt;/TD&gt;&lt;TD&gt;Plugin&lt;/TD&gt;&lt;TD&gt;Solution&lt;/TD&gt;&lt;TD&gt;pic&lt;/TD&gt;&lt;TD&gt;email&lt;/TD&gt;&lt;TD&gt;squad&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;192.168.1.12&lt;/TD&gt;&lt;TD&gt;PluginA&lt;/TD&gt;&lt;TD&gt;somesolution2&lt;/TD&gt;&lt;TD&gt;somePIC&lt;/TD&gt;&lt;TD&gt;email2@fake.com&lt;/TD&gt;&lt;TD&gt;Squad1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Then,&amp;nbsp;&lt;A href="http://localhost:8000/en-US/app/search/search_based_on_token?hostnameToken=host3" target="_blank" rel="noopener"&gt;http://localhost:8000/en-US/app/search/search_based_on_token?hostnameToken=host3&lt;/A&gt;&amp;nbsp;has no return in the left-hand side panel. &amp;nbsp;If you want to not run the search and hide the panel when this happens, you can set and unset conditional tokens and follow&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Viz/ContextualDrilldown#Show_or_hide_content" target="_blank" rel="noopener"&gt;Show or hide content&lt;/A&gt;.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 01 Sep 2022 12:20:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Which-Condition-Function-for-seach-based-on-Token-should-I-use/m-p/611599#M212630</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-09-01T12:20:14Z</dc:date>
    </item>
  </channel>
</rss>

