<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to pass a token in one dashboard that will impact other panel based on values? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/636847#M221164</link>
    <description>&lt;P&gt;Hi There,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; I had a panel "OS", that gives the value os,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;based on the value of os,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if it were "Windows" it should display a panel "defender version", not "Agent version"&lt;/P&gt;
&lt;P&gt;If it were&amp;nbsp; "MAC" it should display "Agent version", not&amp;nbsp;"defender version"&lt;/P&gt;
&lt;P&gt;I don't need drop down by selecting the values in "OS" panel, The os values wants to make impact on choosing the panel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance!&lt;/P&gt;</description>
    <pubDate>Fri, 31 Mar 2023 16:50:07 GMT</pubDate>
    <dc:creator>smanojkumar</dc:creator>
    <dc:date>2023-03-31T16:50:07Z</dc:date>
    <item>
      <title>How to pass a token in one dashboard that will impact other panel based on values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/636847#M221164</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; I had a panel "OS", that gives the value os,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;based on the value of os,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if it were "Windows" it should display a panel "defender version", not "Agent version"&lt;/P&gt;
&lt;P&gt;If it were&amp;nbsp; "MAC" it should display "Agent version", not&amp;nbsp;"defender version"&lt;/P&gt;
&lt;P&gt;I don't need drop down by selecting the values in "OS" panel, The os values wants to make impact on choosing the panel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance!&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 16:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/636847#M221164</guid>
      <dc:creator>smanojkumar</dc:creator>
      <dc:date>2023-03-31T16:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: passing a token in one dashboard and it will impact other panel based on values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/636848#M221165</link>
      <description>&lt;P&gt;Please share what you currently have i.e. what searches and panels have you already created?&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 09:39:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/636848#M221165</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-31T09:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: passing a token in one dashboard and it will impact other panel based on values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/636851#M221166</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;The pannel "OS" is&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup lookupfilekvstore
| fields name, os
| search name IN ($name$)
| table os&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;, the panel when os="Windows"&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup lookupfilekvstore
| fields name, defender
| search name IN ($name$)
| table defender&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;, the panel when os="MAC" OR "OS - X"&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup lookupfilekvstore
| fields name, agent
| search name IN ($name$)
| table agent&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 07 Apr 2023 09:29:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/636851#M221166</guid>
      <dc:creator>smanojkumar</dc:creator>
      <dc:date>2023-04-07T09:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: passing a token in one dashboard and it will impact other panel based on values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/636853#M221168</link>
      <description>&lt;P&gt;If you are using SimpleXML dashboards, you can add a done handler to the first search which sets tokens depending on the os, and have depends attributes on the Windows and Mac panels to show them as appropriate.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 09:58:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/636853#M221168</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-31T09:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: passing a token in one dashboard and it will impact other panel based on values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/638296#M221230</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Can you please help me in adding the done handler in the search,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 06:03:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/638296#M221230</guid>
      <dc:creator>smanojkumar</dc:creator>
      <dc:date>2023-04-03T06:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: passing a token in one dashboard and it will impact other panel based on values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/638307#M221233</link>
      <description>&lt;LI-CODE lang="markup"&gt;  &amp;lt;search&amp;gt;
    &amp;lt;query&amp;gt;
| inputlookup lookupfilekvstore
| fields name, os
| search name IN ($name$)
| table os
    &amp;lt;/query&amp;gt;
    &amp;lt;done&amp;gt;
      &amp;lt;eval token="osname"&amp;gt;$result.os$&amp;lt;/eval&amp;gt;
    &amp;lt;/done&amp;gt;
  &amp;lt;/search&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 03 Apr 2023 06:49:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/638307#M221233</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-04-03T06:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: passing a token in one dashboard and it will impact other panel based on values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/639181#M221467</link>
      <description>&lt;P&gt;I tried using, I'm having some error, here is the full query&lt;BR /&gt;I need Agent version panel when os is "MAC" or "OS X" or "IOS" , i need defender sig version if the os is "windows" or "windows 7" or "windows*"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;form theme="dark"&amp;gt;
  &amp;lt;label&amp;gt; ASSET STATUS&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false" autoRun="true"&amp;gt;
    &amp;lt;input type="radio" token="category" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;Category&amp;lt;/label&amp;gt;
      &amp;lt;choice value="work"&amp;gt;Work&amp;lt;/choice&amp;gt;
      &amp;lt;choice value="auto"&amp;gt;Auto&amp;lt;/choice&amp;gt;
      &amp;lt;choice value="server"&amp;gt;Server&amp;lt;/choice&amp;gt;
      &amp;lt;search&amp;gt;
        &amp;lt;query/&amp;gt;
        &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/search&amp;gt;
      &amp;lt;default&amp;gt;work&amp;lt;/default&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;condition value="work"&amp;gt;
          &amp;lt;set token="Work"&amp;gt;"Work"&amp;lt;/set&amp;gt;
          &amp;lt;unset token="Auto"&amp;gt;&amp;lt;/unset&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition value="auto"&amp;gt;
          &amp;lt;set token="Auto"&amp;gt;"Auto"&amp;lt;/set&amp;gt;
          &amp;lt;unset token="Work"&amp;gt;&amp;lt;/unset&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition value="server"&amp;gt;
          &amp;lt;set token="Server"&amp;gt;"Server"&amp;lt;/set&amp;gt;
          &amp;lt;unset token="Work"&amp;gt;&amp;lt;/unset&amp;gt;
          &amp;lt;unset token="Auto"&amp;gt;&amp;lt;/unset&amp;gt;
        &amp;lt;/condition&amp;gt;
      &amp;lt;/change&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="text" token="src_name" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;src_name&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
&amp;lt;row&amp;gt;
              &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;OS&amp;lt;/title&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| inputlookup $category$_sanity_check_kvstore
| fields src_name, os
| search src_name IN ($src_name$)
| table os&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="colorMode"&amp;gt;block&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeColors"&amp;gt;["0xdc4e41","0x53a051"]&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeValues"&amp;gt;[0]&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
&amp;lt;/row&amp;gt;
&amp;lt;row&amp;gt;
    &amp;lt;panel depends="$Work$"&amp;gt;
      &amp;lt;title&amp;gt;Defender Sig Version&amp;lt;/title&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| inputlookup $category$_sanity_check_kvstore
| fields src_name, defender_sig_version_check
| search src_name IN ($src_name$)
| table defender_sig_version_check&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="colorMode"&amp;gt;block&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeColors"&amp;gt;["0xdc4e41","0x53a051"]&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeValues"&amp;gt;[0]&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Agent Version&amp;lt;/title&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| inputlookup $category$_sanity_check_kvstore
| fields agentVersion_value,base_agentVersion_value, src_name
| search src_name IN ($src_name$)
| eval edr_mac_check=if(agentVersion_value&amp;amp;gt;=base_agentVersion_value,3,0)
| table edr_mac_check&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="colorMode"&amp;gt;block&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeColors"&amp;gt;["0xdc4e41","0x53a051"]&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeValues"&amp;gt;[0]&amp;lt;/option&amp;gt;
        &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 07 Apr 2023 09:32:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/639181#M221467</guid>
      <dc:creator>smanojkumar</dc:creator>
      <dc:date>2023-04-07T09:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: passing a token in one dashboard and it will impact other panel based on values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/639185#M221471</link>
      <description>&lt;P&gt;How does this implement the suggestions made?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 09:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/639185#M221471</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-04-07T09:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: passing a token in one dashboard and it will impact other panel based on values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/639187#M221473</link>
      <description>&lt;P&gt;Error in the sense, how to select panel based on the output of OS, I need that as well, we are done with passing the result and need help to select panel based on the output of OS&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 09:25:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-a-token-in-one-dashboard-that-will-impact-other/m-p/639187#M221473</guid>
      <dc:creator>smanojkumar</dc:creator>
      <dc:date>2023-04-07T09:25:42Z</dc:date>
    </item>
  </channel>
</rss>

