<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dashboard Studio Dropdown default value from lookup table in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-Studio-Dropdown-default-value-from-lookup-table/m-p/674865#M230984</link>
    <description>&lt;P&gt;Ok this is ugly but should be functionable.&amp;nbsp; After researching I wasn't able to find a method to dynamically assign the default value, but you can default to the first value of the search result.&lt;/P&gt;&lt;P&gt;Source Table&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Name&lt;/TD&gt;&lt;TD width="50%"&gt;Value&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Name 01&lt;/TD&gt;&lt;TD width="50%"&gt;Value 01&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Name 02&lt;/TD&gt;&lt;TD width="50%"&gt;value 02&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Name 03&lt;/TD&gt;&lt;TD width="50%"&gt;value03&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Name 04&lt;/TD&gt;&lt;TD width="50%"&gt;Value04&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set your data source to pull from a search designed like the following - modify for your needs.&lt;/P&gt;&lt;PRE&gt;| inputlookup input_test_values.csv &lt;BR /&gt;| stats values(Value) as Value &lt;BR /&gt;| format &lt;BR /&gt;| rename search as Value &lt;BR /&gt;| eval Name="All" &lt;BR /&gt;| table Name Value &lt;BR /&gt;| append&lt;BR /&gt;   [| inputlookup input_test_values.csv &lt;BR /&gt;    | table Name Value ]&lt;/PRE&gt;&lt;P&gt;Search Output:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Name&lt;/TD&gt;&lt;TD&gt;Value&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;All&lt;/TD&gt;&lt;TD&gt;( ( ( Value="Value 01" OR Value="Value04" OR Value="value 02" OR Value="value03" ) ) )&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name 01&lt;/TD&gt;&lt;TD&gt;Value 01&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name 02&lt;/TD&gt;&lt;TD&gt;value 02&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name 03&lt;/TD&gt;&lt;TD&gt;value03&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name 04&lt;/TD&gt;&lt;TD&gt;Value04&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your inputs config panel to the right should be able to select "First Value" as the default.&amp;nbsp; The search as written can display "All" in the drop down while dynamically building the first value based upon the contents of the lookup no matter how many times it is edited.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way I have written makes the first value very easy to drop into a subsequent search string.&amp;nbsp; Your needs may vary so you can play with the format command to get that output as you need it specifically.&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jan 2024 18:02:39 GMT</pubDate>
    <dc:creator>dural_yyz</dc:creator>
    <dc:date>2024-01-19T18:02:39Z</dc:date>
    <item>
      <title>Dashboard Studio Dropdown default value from lookup table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-Studio-Dropdown-default-value-from-lookup-table/m-p/674850#M230982</link>
      <description>&lt;P&gt;I am trying to replace default value of drop down with all the values from a column in lookup table&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;Lookup table&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="44.443129208754215%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="34px"&gt;Name&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="34px"&gt;log_group&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;Name 1&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;Log1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;Name 2&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;log 2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;Name 3&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;log3&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need drop down default taken as log1,log2,log3&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 15:56:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-Studio-Dropdown-default-value-from-lookup-table/m-p/674850#M230982</guid>
      <dc:creator>splunkuser320</dc:creator>
      <dc:date>2024-01-19T15:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Studio Dropdown default value from lookup table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-Studio-Dropdown-default-value-from-lookup-table/m-p/674865#M230984</link>
      <description>&lt;P&gt;Ok this is ugly but should be functionable.&amp;nbsp; After researching I wasn't able to find a method to dynamically assign the default value, but you can default to the first value of the search result.&lt;/P&gt;&lt;P&gt;Source Table&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Name&lt;/TD&gt;&lt;TD width="50%"&gt;Value&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Name 01&lt;/TD&gt;&lt;TD width="50%"&gt;Value 01&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Name 02&lt;/TD&gt;&lt;TD width="50%"&gt;value 02&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Name 03&lt;/TD&gt;&lt;TD width="50%"&gt;value03&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Name 04&lt;/TD&gt;&lt;TD width="50%"&gt;Value04&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set your data source to pull from a search designed like the following - modify for your needs.&lt;/P&gt;&lt;PRE&gt;| inputlookup input_test_values.csv &lt;BR /&gt;| stats values(Value) as Value &lt;BR /&gt;| format &lt;BR /&gt;| rename search as Value &lt;BR /&gt;| eval Name="All" &lt;BR /&gt;| table Name Value &lt;BR /&gt;| append&lt;BR /&gt;   [| inputlookup input_test_values.csv &lt;BR /&gt;    | table Name Value ]&lt;/PRE&gt;&lt;P&gt;Search Output:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Name&lt;/TD&gt;&lt;TD&gt;Value&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;All&lt;/TD&gt;&lt;TD&gt;( ( ( Value="Value 01" OR Value="Value04" OR Value="value 02" OR Value="value03" ) ) )&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name 01&lt;/TD&gt;&lt;TD&gt;Value 01&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name 02&lt;/TD&gt;&lt;TD&gt;value 02&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name 03&lt;/TD&gt;&lt;TD&gt;value03&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name 04&lt;/TD&gt;&lt;TD&gt;Value04&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your inputs config panel to the right should be able to select "First Value" as the default.&amp;nbsp; The search as written can display "All" in the drop down while dynamically building the first value based upon the contents of the lookup no matter how many times it is edited.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way I have written makes the first value very easy to drop into a subsequent search string.&amp;nbsp; Your needs may vary so you can play with the format command to get that output as you need it specifically.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 18:02:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-Studio-Dropdown-default-value-from-lookup-table/m-p/674865#M230984</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-01-19T18:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Studio Dropdown default value from lookup table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-Studio-Dropdown-default-value-from-lookup-table/m-p/674905#M230992</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;I need drop down default taken as log1,log2,log3&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194981"&gt;@dural_yyz&lt;/a&gt;&amp;nbsp;hinted at, the actual solution depends very much on how you will use the input token in search. &amp;nbsp;If you want the comma delimited list as part of &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/ConditionalFunctions#in.28.26lt.3Bfield.26gt.3B.2C.26lt.3Blist.26gt.3B.29" target="_blank" rel="noopener"&gt;IN&lt;/A&gt; function, you can just use &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Appendpipe" target="_blank" rel="noopener"&gt;appendpipe&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup mylookup
| appendpipe
    [stats values(log_group) as log_group
    | eval Name = "Any", log_group = mvjoin(log_group, ",")]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You get&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Name&lt;/TD&gt;&lt;TD&gt;log_group&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name 1&lt;/TD&gt;&lt;TD&gt;Log1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name 2&lt;/TD&gt;&lt;TD&gt;log2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Name 3&lt;/TD&gt;&lt;TD&gt;log3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Any&lt;/TD&gt;&lt;TD&gt;log1,log2,log3&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2024 01:21:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-Studio-Dropdown-default-value-from-lookup-table/m-p/674905#M230992</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-01-20T01:21:27Z</dc:date>
    </item>
  </channel>
</rss>

