<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to exclude results using checkbox? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-results-using-checkbox/m-p/629319#M218613</link>
    <description>&lt;P&gt;I have the following search which returns a table of all hostnames and operating systems.&lt;/P&gt;
&lt;P&gt;| inputlookup hosts.csv&lt;BR /&gt;| search OS="*server*"&lt;BR /&gt;| table hostname, OS&lt;/P&gt;
&lt;P&gt;I would like to add a checkbox to exclude Windows Server 2008 builds. This is what I have so far:&lt;/P&gt;
&lt;P&gt;&amp;lt;row&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;input type="checkbox" token="checkbox" searchWhenChanged="true"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;choice value="Windows Server 2008*"&amp;gt;Exclude Server 2008&amp;lt;/choice&amp;gt;&lt;BR /&gt;&amp;lt;change&amp;gt;&lt;BR /&gt;&amp;lt;condition match="$checkbox$==&amp;amp;quot;Enabled&amp;amp;quot;"&amp;gt;&lt;BR /&gt;&amp;lt;set token="setToken"&amp;gt;1&amp;lt;/set&amp;gt;&lt;BR /&gt;&amp;lt;/condition&amp;gt;&lt;BR /&gt;&amp;lt;condition&amp;gt;&lt;BR /&gt;&amp;lt;unset token="setToken"&amp;gt;&amp;lt;/unset&amp;gt;&lt;BR /&gt;&amp;lt;/condition&amp;gt;&lt;BR /&gt;&amp;lt;/change&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;/panel&amp;gt;&lt;BR /&gt;&amp;lt;/row&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;New panel to show server builds depending on the checkbox:&lt;/P&gt;
&lt;P&gt;&amp;lt;query&amp;gt;&lt;/P&gt;
&lt;P&gt;| inputlookup hosts.csv&lt;BR /&gt;| search OS="*server*" AND OS!="$checkbox$"&lt;BR /&gt;| stats count as total&lt;/P&gt;
&lt;P&gt;&amp;lt;query&amp;gt;&lt;/P&gt;
&lt;P&gt;This only works when the checkbox is selected and correctly excludes the 2008 builds from the search, but doesn`t display anything when the checkbox is unselected. I would like to display all devices when the&amp;nbsp; checkbox is unselected.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Feb 2023 14:44:34 GMT</pubDate>
    <dc:creator>tomapatan</dc:creator>
    <dc:date>2023-02-02T14:44:34Z</dc:date>
    <item>
      <title>How to exclude results using checkbox?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-results-using-checkbox/m-p/629319#M218613</link>
      <description>&lt;P&gt;I have the following search which returns a table of all hostnames and operating systems.&lt;/P&gt;
&lt;P&gt;| inputlookup hosts.csv&lt;BR /&gt;| search OS="*server*"&lt;BR /&gt;| table hostname, OS&lt;/P&gt;
&lt;P&gt;I would like to add a checkbox to exclude Windows Server 2008 builds. This is what I have so far:&lt;/P&gt;
&lt;P&gt;&amp;lt;row&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;input type="checkbox" token="checkbox" searchWhenChanged="true"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;choice value="Windows Server 2008*"&amp;gt;Exclude Server 2008&amp;lt;/choice&amp;gt;&lt;BR /&gt;&amp;lt;change&amp;gt;&lt;BR /&gt;&amp;lt;condition match="$checkbox$==&amp;amp;quot;Enabled&amp;amp;quot;"&amp;gt;&lt;BR /&gt;&amp;lt;set token="setToken"&amp;gt;1&amp;lt;/set&amp;gt;&lt;BR /&gt;&amp;lt;/condition&amp;gt;&lt;BR /&gt;&amp;lt;condition&amp;gt;&lt;BR /&gt;&amp;lt;unset token="setToken"&amp;gt;&amp;lt;/unset&amp;gt;&lt;BR /&gt;&amp;lt;/condition&amp;gt;&lt;BR /&gt;&amp;lt;/change&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;/panel&amp;gt;&lt;BR /&gt;&amp;lt;/row&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;New panel to show server builds depending on the checkbox:&lt;/P&gt;
&lt;P&gt;&amp;lt;query&amp;gt;&lt;/P&gt;
&lt;P&gt;| inputlookup hosts.csv&lt;BR /&gt;| search OS="*server*" AND OS!="$checkbox$"&lt;BR /&gt;| stats count as total&lt;/P&gt;
&lt;P&gt;&amp;lt;query&amp;gt;&lt;/P&gt;
&lt;P&gt;This only works when the checkbox is selected and correctly excludes the 2008 builds from the search, but doesn`t display anything when the checkbox is unselected. I would like to display all devices when the&amp;nbsp; checkbox is unselected.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 14:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-results-using-checkbox/m-p/629319#M218613</guid>
      <dc:creator>tomapatan</dc:creator>
      <dc:date>2023-02-02T14:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude results using checkbox</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-results-using-checkbox/m-p/629324#M218617</link>
      <description>&lt;LI-CODE lang="markup"&gt;  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;input type="checkbox" token="checkbox" searchWhenChanged="true"&amp;gt;
        &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
        &amp;lt;choice value="Windows Server 2008*"&amp;gt;Exclude Server 2008&amp;lt;/choice&amp;gt;
        &amp;lt;delimiter&amp;gt; &amp;lt;/delimiter&amp;gt;
        &amp;lt;change&amp;gt;
          &amp;lt;condition label="Exclude Server 2008"&amp;gt;
            &amp;lt;set token="tokenFilter"&amp;gt;AND OS!="Windows Server 2008*"&amp;lt;/set&amp;gt;
          &amp;lt;/condition&amp;gt;
          &amp;lt;condition&amp;gt;
            &amp;lt;set token="tokenFilter"&amp;gt;&amp;lt;/set&amp;gt;
          &amp;lt;/condition&amp;gt;
        &amp;lt;/change&amp;gt;
      &amp;lt;/input&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;and adjust your search like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup hosts.csv
| search OS="*server*"  $tokenFilter$
| stats count as total&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 02 Feb 2023 12:43:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-results-using-checkbox/m-p/629324#M218617</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2023-02-02T12:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude results using checkbox</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-results-using-checkbox/m-p/629327#M218619</link>
      <description>&lt;P&gt;Thanks Paul, unfortunately it now does the opposite as before: displays correctly when the checkbox is selected and no content when it`s checked.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 13:08:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-results-using-checkbox/m-p/629327#M218619</guid>
      <dc:creator>tomapatan</dc:creator>
      <dc:date>2023-02-02T13:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude results using checkbox</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-results-using-checkbox/m-p/629332#M218622</link>
      <description>&lt;P&gt;Just use below test dashboard&amp;nbsp; for verification. There might be something wrong in your search or in the input config. Feel free to share your code.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;form version="1.1"&amp;gt;
  &amp;lt;label&amp;gt;Test_checkbox&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;&amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;input type="checkbox" token="checkbox" searchWhenChanged="true"&amp;gt;
        &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
        &amp;lt;choice value="Windows Server 2008*"&amp;gt;Exclude Server 2008&amp;lt;/choice&amp;gt;
        &amp;lt;delimiter&amp;gt; &amp;lt;/delimiter&amp;gt;
        &amp;lt;change&amp;gt;
          &amp;lt;condition label="Exclude Server 2008"&amp;gt;
            &amp;lt;set token="tokenFilter"&amp;gt;AND OS!="Windows Server 2008*"&amp;lt;/set&amp;gt;
          &amp;lt;/condition&amp;gt;
          &amp;lt;condition&amp;gt;
            &amp;lt;set token="tokenFilter"&amp;gt;&amp;lt;/set&amp;gt;
          &amp;lt;/condition&amp;gt;
        &amp;lt;/change&amp;gt;
      &amp;lt;/input&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;event&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal OS="*server*" $tokenFilter$
| stats count as total&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="list.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/event&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 13:21:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-results-using-checkbox/m-p/629332#M218622</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2023-02-02T13:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude results using checkbox</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-results-using-checkbox/m-p/629337#M218623</link>
      <description>&lt;P&gt;Thanks Paul,&lt;BR /&gt;&lt;BR /&gt;I made the mistake of encapsulating $tokenFilter$ in double quotes. Works fine without the quotes.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 13:35:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-exclude-results-using-checkbox/m-p/629337#M218623</guid>
      <dc:creator>tomapatan</dc:creator>
      <dc:date>2023-02-02T13:35:26Z</dc:date>
    </item>
  </channel>
</rss>

