<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: spl qquery in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741890#M240719</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;In below dashboard&lt;BR /&gt;I want To fetch the&amp;nbsp;&lt;SPAN class=""&gt;&lt;STRONG&gt;DistinctAdminUserCount&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;for a specific&amp;nbsp;&lt;SPAN class=""&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;(e.g.,&amp;nbsp;&lt;SPAN class=""&gt;&lt;STRONG&gt;"-target"&lt;/STRONG&gt;&lt;/SPAN&gt;)&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;DistinctAdminUserCount&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Name -target 3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Name -product 2&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Problem 1:with below query it is working if i manually add searchName either test or prod.But if want to work from dashboard the search is not substituting for&amp;nbsp;entityTokennsp&lt;BR /&gt;Problem2:search Name can be&amp;nbsp; test or prod based on env selection that also need to be fixed&lt;BR /&gt;if it is test,search Name="*-test-target"&lt;BR /&gt;if it is pro,search Name="*-prod-target"&lt;BR /&gt;&lt;BR /&gt;Appraoch:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use the&lt;SPAN&gt;&amp;nbsp;entityToken&lt;SPAN&gt;&amp;nbsp;token to store the dropdown value (e.g.,&lt;SPAN&gt;&amp;nbsp;target).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Dynamically derive the required values (target&lt;SPAN&gt;&amp;nbsp;or&lt;SPAN&gt;&amp;nbsp;*-test-targetfob) directly in the queries using the&lt;SPAN&gt;&amp;nbsp;eval&lt;SPAN&gt;&amp;nbsp;and&lt;SPAN&gt;&amp;nbsp;case&lt;SPAN&gt;&amp;nbsp;commands.&lt;BR /&gt;&lt;BR /&gt;entityToken is correctly substituted in dashboard&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P class=""&gt;entityTokennsp is not substituted under below query&lt;BR /&gt;Query used in Dashboard:&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI-CODE lang="markup"&gt;          &amp;lt;query&amp;gt;index="np" source="**" sourcetype="n"
| spath path=test.nsp3s{} output=nsp3s
| mvexpand nsp3s
| spath input=nsp3s path=Name output=Name
| spath input=nsp3s path=DistinctAdminUserCount output=DistinctAdminUserCount
| search Name=$entityTokennsp$
| sort -_time
| head 1
| fields DistinctAdminUserCount&amp;lt;/query&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;splunk query working in search separately if i given name manually:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="np" source="**" sourcetype="n"
| spath path=test.nsp3s{} output=nsp3s
| mvexpand nsp3s
| spath input=nsp3s path=Name output=Name
| spath input=nsp3s path=DistinctAdminUserCount output=DistinctAdminUserCount
| search Name="-test-target"
| sort -_time
| head 1
| fields DistinctAdminUserCount&lt;/LI-CODE&gt;&lt;P&gt;Das&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;form version="1.1" theme="dark"&amp;gt;
  &amp;lt;label&amp;gt;Stats &amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="true"&amp;gt;
    &amp;lt;input type="dropdown" token="indexToken1" searchWhenChanged="false"&amp;gt;
      &amp;lt;label&amp;gt;Environment&amp;lt;/label&amp;gt;
      &amp;lt;choice value="prod,prod"&amp;gt;PROD&amp;lt;/choice&amp;gt;
      &amp;lt;choice value="np,test"&amp;gt;TEST&amp;lt;/choice&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;eval token="stageToken"&amp;gt;mvindex(split($value$,","),1)&amp;lt;/eval&amp;gt;
        &amp;lt;eval token="indexToken"&amp;gt;mvindex(split($value$,","),0)&amp;lt;/eval&amp;gt;
      &amp;lt;/change&amp;gt;
      &amp;lt;default&amp;gt;np,test&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
 &amp;lt;input type="dropdown" token="entityToken" searchWhenChanged="false"&amp;gt;
      &amp;lt;label&amp;gt;Data Entity&amp;lt;/label&amp;gt;
      &amp;lt;choice value="targetFO"&amp;gt;Target FO&amp;lt;/choice&amp;gt;
      &amp;lt;choice value="productFO"&amp;gt;Product FO&amp;lt;/choice&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;eval token="entityToken"&amp;gt;case(
      
      $value$=="targetFO", "Target",
      $value$=="productFO", "Product",
      true(), ""
    )&amp;lt;/eval&amp;gt;
        &amp;lt;!-- Token for the second query --&amp;gt;
        &amp;lt;eval token="entityTokennsp"&amp;gt;case(
      "entityToken"=="targetFO", "test-target",
      "entityToken"=="productFO", "test-product",
      true(), ""
    )&amp;lt;/eval&amp;gt;
      &amp;lt;/change&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;/fieldset&amp;gt;
    &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;title&amp;gt;Distinct Consumer Coun&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index="np" source="**" sourcetype="n"
| spath path=test.nsp3s{} output=nsp3s
| mvexpand nsp3s
| spath input=nsp3s path=Name output=Name
| spath input=nsp3s path=DistinctAdminUserCount output=DistinctAdminUserCount
| search Name=$entityTokennsp$
| sort -_time
| head 1
| fields DistinctAdminUserCount&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$timeToken.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$timeToken.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;/row&amp;gt;
&amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Total Request :&amp;lt;/title&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=np    source IN ("*-$stageToken$-$entityToken$") msg="data:invoke" | stats count&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$timeToken.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$timeToken.latest$&amp;lt;/latest&amp;gt;
          &amp;lt;refresh&amp;gt;60m&amp;lt;/refresh&amp;gt;
          &amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="colorMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="height"&amp;gt;317&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeColors"&amp;gt;["0xcba700","0xdc4e41"]&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeValues"&amp;gt;[200]&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.size"&amp;gt;large&amp;lt;/option&amp;gt;
        &amp;lt;option name="unitPosition"&amp;gt;after&amp;lt;/option&amp;gt;
        &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 15 Mar 2025 16:15:57 GMT</pubDate>
    <dc:creator>nithys</dc:creator>
    <dc:date>2025-03-15T16:15:57Z</dc:date>
    <item>
      <title>spl qquery</title>
      <link>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741743#M240702</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Need help in finding&amp;nbsp;DistinctAdminUserCount and&amp;nbsp;DistinctAdminUserNames of each associated Name inside test or prod object&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{"prod":{},"test":{"DistinctAdminUser":["streaming","Create","","Application.","App.","App.","obi","Users","platform",],"TotalSinkAdminUsers":33,"TotalNSP3Count":11,"TotalSourceAdminUsers":10,"DistinctAdminUserCount":11,"TotalStreamAdminUsers":12,"TotalAdminUser":55,"nsp3s":[{"StreamAdminUserNames":["App."],"SourceAdminUserNames":["preprod"],"DistinctAdminUserCount":5,"SinkAdminUserCount":5,"SourceAdminUserCount":1,"DistinctAdminUserNames”:[“Technology”,”2”,3””,”4”,”5”],”StreamAdminUserCount":1,"TotalAdminUserCount":7,"SinkAdminUserNames":["obi"],"Name”:”hi-cost-test-sample“},{“StreamAdminUserNames":["preprod"],"SourceAdminUserNames":["admin.preprod"],"DistinctAdminUserCount":3,"SinkAdminUserCount":3,"SourceAdminUserCount":1,"DistinctAdminUserNames":["preprod”,2”,3””,”4”,”5”],”StreamAdminUserCount":1,"TotalAdminUserCount":5,"SinkAdminUserNames":["ops-tform"],"Name”:”hi-cost-test-name”},”subscriberId":"NSP3"}&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-03-13 at 4.10.40 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38183iDF24AD491072ACD8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-03-13 at 4.10.40 PM.png" alt="Screenshot 2025-03-13 at 4.10.40 PM.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="*" source="*"
| spath test.nsps{} output=nsps
| mvexpand nsps
| spath input=nsps Name output=Name
| spath input=nsps ReadOnlyConsumerNames{} output=ReadOnlyConsumerNames
| search Name=""
| stats values(ReadOnlyConsumerNames) as ReadOnlyConsumerNames by Name
| rename Name as EntityName
| table EntityName ReadOnlyConsumerNames&lt;/LI-CODE&gt;&lt;P&gt;Need&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 23:27:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741743#M240702</guid>
      <dc:creator>nithys</dc:creator>
      <dc:date>2025-03-13T23:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: spl qquery</title>
      <link>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741773#M240703</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260549"&gt;@nithys&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what are the results of your search?&lt;/P&gt;&lt;P&gt;what is your issue?&lt;/P&gt;&lt;P&gt;You shared a search that seems to be correct, does it give you results?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 07:00:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741773#M240703</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-03-14T07:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: spl qquery</title>
      <link>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741804#M240704</link>
      <description>&lt;P&gt;I am looking to have three column one for Name(EntityName) another for&amp;nbsp;&lt;SPAN&gt;DistinctAdminUserNames and third one for DistinctAdminUserCount of each associated Name inside test or prod object.can you modify query in order to fetch like below&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;Name&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&lt;SPAN&gt;DistinctAdminUserNames&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&lt;SPAN&gt;DistinctAdminUserCount&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;&lt;P class=""&gt;hi-cost-test-sample&lt;/P&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&lt;P class=""&gt;“Technology”,”2”,3””,”4”,”5”&lt;/P&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;5&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P class=""&gt;hi-cost-test-name&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;getting error as shown in picture&lt;BR /&gt;[idx-i-010ab3eb96c032aa1.om,idx-i-021ad0bda97800234.nike.splunkcloud.com,idx-i-0267c01401cb1d8ed..com,idx-i-06c8fc857ab0b62ea.nike.splunkcloud.com,idx-i-0804ced14f96f4517.kcloud.com,idx-i-0a6073abaabb5902b.nike.splunkcloud.com,idx-i-0ea40148068176b7f.noud.com] Field 'nsp3s' does not exist in the data.&lt;BR /&gt;&lt;BR /&gt;query&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="*" source="**" sourcetype="*"
| spath test.nsp3s{} output=nsps3s
| mvexpand nsp3s
| spath input=nsp3s Name output=Name
| spath input=nsp3s DistinctAdminUserNames{} output=DistinctAdminUserNames
| search Name="hi-cost-test-sampleDistinctAdminUserNamesDistinctAdminUserNamesDistinctAdminUserNamesDistinctAdminUserNames"
| stats values(DistinctAdminUserNames) as DistinctAdminUserNames by Name
| rename Name as EntityName
| table EntityName DistinctAdminUserNames&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;splunk data&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{"prod":{},"test":{"DistinctAdminUser":["streaming","Create","","Application.","App.","App.","obi","Users","platform",],"TotalSinkAdminUsers":33,"TotalNSP3Count":11,"TotalSourceAdminUsers":10,"DistinctAdminUserCount":11,"TotalStreamAdminUsers":12,"TotalAdminUser":55,"nsp3s":[{"StreamAdminUserNames":["App."],"SourceAdminUserNames":["preprod"],"DistinctAdminUserCount":5,"SinkAdminUserCount":5,"SourceAdminUserCount":1,"DistinctAdminUserNames”:[“Technology”,”2”,3””,”4”,”5”],”StreamAdminUserCount":1,"TotalAdminUserCount":7,"SinkAdminUserNames":["obi"],"Name”:”hi-cost-test-sample“},{“StreamAdminUserNames":["preprod"],"SourceAdminUserNames":["admin.preprod"],"DistinctAdminUserCount":3,"SinkAdminUserCount":3,"SourceAdminUserCount":1,"DistinctAdminUserNames":["preprod”,2”,3””,”4”,”5”],”StreamAdminUserCount":1,"TotalAdminUserCount":5,"SinkAdminUserNames":["ops-tform"],"Name”:”hi-cost-test-name”},”subscriberId":"NSP3"}&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 12:43:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741804#M240704</guid>
      <dc:creator>nithys</dc:creator>
      <dc:date>2025-03-14T12:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: spl qquery</title>
      <link>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741805#M240705</link>
      <description>&lt;P&gt;Help to modify existing query to add all&amp;nbsp;Name,&lt;SPAN&gt;DistinctAdminUserNames,&lt;/SPAN&gt;&lt;SPAN&gt;DistinctAdminUserCount&lt;BR /&gt;&lt;BR /&gt;when trying with search = "hi-cost-test-sample" OR "hi-cost-test-name" .It didnt work&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;Name&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&lt;SPAN&gt;DistinctAdminUserNames&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&lt;SPAN&gt;DistinctAdminUserCount&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;&lt;P class=""&gt;hi-cost-test-sample&lt;/P&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&lt;P class=""&gt;“Technology”,”2”,3””,”4”,”5”&lt;/P&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;5&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P class=""&gt;hi-cost-test-name&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class=""&gt;"preprod”,2”,3””,”4”,”5”&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="*" source="**" sourcetype="*"
| spath test.nsp3s{} output=nsps3s
| mvexpand nsp3s
| spath input=nsp3s Name output=Name
| spath input=nsp3s DistinctAdminUserNames{} output=DistinctAdminUserNames
| search Name="hi-cost-test-sample" OR "hi-cost-test-name"
| stats values(DistinctAdminUserNames) as DistinctAdminUserNames by Name
| rename Name as EntityName
| table EntityName DistinctAdminUserNames&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 12:49:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741805#M240705</guid>
      <dc:creator>nithys</dc:creator>
      <dc:date>2025-03-14T12:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: spl qquery</title>
      <link>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741820#M240706</link>
      <description>&lt;P&gt;OK. Several things here...&lt;/P&gt;&lt;P&gt;1. You have a "stars galore" in your initial search. Even if your role limits your access to just one kind of data, searching through all indexes, all sourcetypes and all sources is not a very good practice. You should be as specific as possible to make your searches fast. Especially if you use heavy commands like spath.&lt;/P&gt;&lt;P&gt;2. You use inconsistent field names (nsps3s vs nsp3s) - check if it's in the original search or is it just a typo here.&lt;/P&gt;&lt;P&gt;3. Your data sample is not a valid json.&lt;/P&gt;&lt;P&gt;4. Two separate spath commands will create two separate multivalued fields. Splunk keeps no "relation" between values in those commands.&lt;/P&gt;&lt;P&gt;5. Your search should say&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search Name="hi-cost-test-sample" OR Name="hi-cost-test-name"&lt;/LI-CODE&gt;&lt;P&gt;(still - see p.4)&lt;/P&gt;&lt;P&gt;6. When you get your DistinctAdminUserNames correctly you can get DistinctAdminUserCount by using mvcount() function.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 14:44:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741820#M240706</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-03-14T14:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: spl qquery</title>
      <link>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741890#M240719</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;In below dashboard&lt;BR /&gt;I want To fetch the&amp;nbsp;&lt;SPAN class=""&gt;&lt;STRONG&gt;DistinctAdminUserCount&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;for a specific&amp;nbsp;&lt;SPAN class=""&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;(e.g.,&amp;nbsp;&lt;SPAN class=""&gt;&lt;STRONG&gt;"-target"&lt;/STRONG&gt;&lt;/SPAN&gt;)&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;DistinctAdminUserCount&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Name -target 3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Name -product 2&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Problem 1:with below query it is working if i manually add searchName either test or prod.But if want to work from dashboard the search is not substituting for&amp;nbsp;entityTokennsp&lt;BR /&gt;Problem2:search Name can be&amp;nbsp; test or prod based on env selection that also need to be fixed&lt;BR /&gt;if it is test,search Name="*-test-target"&lt;BR /&gt;if it is pro,search Name="*-prod-target"&lt;BR /&gt;&lt;BR /&gt;Appraoch:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use the&lt;SPAN&gt;&amp;nbsp;entityToken&lt;SPAN&gt;&amp;nbsp;token to store the dropdown value (e.g.,&lt;SPAN&gt;&amp;nbsp;target).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Dynamically derive the required values (target&lt;SPAN&gt;&amp;nbsp;or&lt;SPAN&gt;&amp;nbsp;*-test-targetfob) directly in the queries using the&lt;SPAN&gt;&amp;nbsp;eval&lt;SPAN&gt;&amp;nbsp;and&lt;SPAN&gt;&amp;nbsp;case&lt;SPAN&gt;&amp;nbsp;commands.&lt;BR /&gt;&lt;BR /&gt;entityToken is correctly substituted in dashboard&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P class=""&gt;entityTokennsp is not substituted under below query&lt;BR /&gt;Query used in Dashboard:&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI-CODE lang="markup"&gt;          &amp;lt;query&amp;gt;index="np" source="**" sourcetype="n"
| spath path=test.nsp3s{} output=nsp3s
| mvexpand nsp3s
| spath input=nsp3s path=Name output=Name
| spath input=nsp3s path=DistinctAdminUserCount output=DistinctAdminUserCount
| search Name=$entityTokennsp$
| sort -_time
| head 1
| fields DistinctAdminUserCount&amp;lt;/query&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;splunk query working in search separately if i given name manually:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="np" source="**" sourcetype="n"
| spath path=test.nsp3s{} output=nsp3s
| mvexpand nsp3s
| spath input=nsp3s path=Name output=Name
| spath input=nsp3s path=DistinctAdminUserCount output=DistinctAdminUserCount
| search Name="-test-target"
| sort -_time
| head 1
| fields DistinctAdminUserCount&lt;/LI-CODE&gt;&lt;P&gt;Das&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;form version="1.1" theme="dark"&amp;gt;
  &amp;lt;label&amp;gt;Stats &amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="true"&amp;gt;
    &amp;lt;input type="dropdown" token="indexToken1" searchWhenChanged="false"&amp;gt;
      &amp;lt;label&amp;gt;Environment&amp;lt;/label&amp;gt;
      &amp;lt;choice value="prod,prod"&amp;gt;PROD&amp;lt;/choice&amp;gt;
      &amp;lt;choice value="np,test"&amp;gt;TEST&amp;lt;/choice&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;eval token="stageToken"&amp;gt;mvindex(split($value$,","),1)&amp;lt;/eval&amp;gt;
        &amp;lt;eval token="indexToken"&amp;gt;mvindex(split($value$,","),0)&amp;lt;/eval&amp;gt;
      &amp;lt;/change&amp;gt;
      &amp;lt;default&amp;gt;np,test&amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
 &amp;lt;input type="dropdown" token="entityToken" searchWhenChanged="false"&amp;gt;
      &amp;lt;label&amp;gt;Data Entity&amp;lt;/label&amp;gt;
      &amp;lt;choice value="targetFO"&amp;gt;Target FO&amp;lt;/choice&amp;gt;
      &amp;lt;choice value="productFO"&amp;gt;Product FO&amp;lt;/choice&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;eval token="entityToken"&amp;gt;case(
      
      $value$=="targetFO", "Target",
      $value$=="productFO", "Product",
      true(), ""
    )&amp;lt;/eval&amp;gt;
        &amp;lt;!-- Token for the second query --&amp;gt;
        &amp;lt;eval token="entityTokennsp"&amp;gt;case(
      "entityToken"=="targetFO", "test-target",
      "entityToken"=="productFO", "test-product",
      true(), ""
    )&amp;lt;/eval&amp;gt;
      &amp;lt;/change&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;/fieldset&amp;gt;
    &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;title&amp;gt;Distinct Consumer Coun&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index="np" source="**" sourcetype="n"
| spath path=test.nsp3s{} output=nsp3s
| mvexpand nsp3s
| spath input=nsp3s path=Name output=Name
| spath input=nsp3s path=DistinctAdminUserCount output=DistinctAdminUserCount
| search Name=$entityTokennsp$
| sort -_time
| head 1
| fields DistinctAdminUserCount&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$timeToken.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$timeToken.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;/row&amp;gt;
&amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Total Request :&amp;lt;/title&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=np    source IN ("*-$stageToken$-$entityToken$") msg="data:invoke" | stats count&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$timeToken.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$timeToken.latest$&amp;lt;/latest&amp;gt;
          &amp;lt;refresh&amp;gt;60m&amp;lt;/refresh&amp;gt;
          &amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="colorMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="height"&amp;gt;317&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeColors"&amp;gt;["0xcba700","0xdc4e41"]&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeValues"&amp;gt;[200]&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.size"&amp;gt;large&amp;lt;/option&amp;gt;
        &amp;lt;option name="unitPosition"&amp;gt;after&amp;lt;/option&amp;gt;
        &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Mar 2025 16:15:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/spl-qquery/m-p/741890#M240719</guid>
      <dc:creator>nithys</dc:creator>
      <dc:date>2025-03-15T16:15:57Z</dc:date>
    </item>
  </channel>
</rss>

