<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set a token from a base search in my dashboard to be consumed in an HTML panel? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232330#M68903</link>
    <description>&lt;P&gt;Hello Steve,&lt;/P&gt;

&lt;P&gt;You just need to include a condition for matching and set the token. for eg: below is a working example&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;TEST&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=* |stats count by sourcetype&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-60m@m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;finalized &amp;gt;
                    &amp;lt;condition match=" 'job.resultCount' != 0"&amp;gt;
                            &amp;lt;set token="tok_wimg"&amp;gt;$result.sourcetype$&amp;lt;/set&amp;gt;
                     &amp;lt;/condition&amp;gt;
                     &amp;lt;condition&amp;gt;
                            &amp;lt;set token="tok_wimg"&amp;gt;No result found&amp;lt;/set&amp;gt;
                     &amp;lt;/condition&amp;gt;
          &amp;lt;/finalized &amp;gt;           
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;html&amp;gt;
      &amp;lt;h1&amp;gt;$tok_wimg$&amp;lt;/h1&amp;gt;
    &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The html panel will display the token name just during the execution time since you are setting the token on search finalization. If you do not want to display at all, just hide the panel until search is finished using the tokens.&lt;/P&gt;

&lt;P&gt;See here for details&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.3/Viz/EventHandlerReference#Search_event_handlers"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.3/Viz/EventHandlerReference#Search_event_handlers&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Aug 2016 12:13:55 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2016-08-18T12:13:55Z</dc:date>
    <item>
      <title>How to set a token from a base search in my dashboard to be consumed in an HTML panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232329#M68902</link>
      <description>&lt;P&gt;hi there, &lt;/P&gt;

&lt;P&gt;I want to display an image based on the result of a search. My dashboard has a "base search" which is used in multiple visualizations on the dashboard:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    &amp;lt;search id="BaseSearch"&amp;gt;
        &amp;lt;query&amp;gt;  
.... | stats last(_time) as latest BY    current_observation.display_location.city    current_observation.dewpoint_c   current_observation.feelslike_c    current_observation.icon_url   current_observation.image.url   current_observation.weather  
      &amp;lt;/query&amp;gt;
        &amp;lt;earliest&amp;gt;$tok_time.earliest$&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;$tok_time.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;finalized&amp;gt;
                   &amp;lt;set token="tok_wimg"&amp;gt;$result.current_observation.icon_url$&amp;lt;/set&amp;gt;
        &amp;lt;/finalized&amp;gt;     
      &amp;lt;/search&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;.... and an html panel:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  &amp;lt;html&amp;gt;
   $tok_wimg$
  &amp;lt;/html&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When executing the dashboard, I see that the html panel shows:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;$result.current_observation.icon_url$&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;but not the content, so I guess that:&lt;/P&gt;

&lt;P&gt;a) setting the token does not work like this?&lt;BR /&gt;
or &lt;BR /&gt;
b) I need to find a way to render the html panel when the search has finished?&lt;/P&gt;

&lt;P&gt;Do you have any suggestions? &lt;/P&gt;

&lt;P&gt;thanks&lt;BR /&gt;
steve &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:39:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232329#M68902</guid>
      <dc:creator>swe</dc:creator>
      <dc:date>2020-09-29T10:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a token from a base search in my dashboard to be consumed in an HTML panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232330#M68903</link>
      <description>&lt;P&gt;Hello Steve,&lt;/P&gt;

&lt;P&gt;You just need to include a condition for matching and set the token. for eg: below is a working example&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;TEST&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=* |stats count by sourcetype&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-60m@m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;finalized &amp;gt;
                    &amp;lt;condition match=" 'job.resultCount' != 0"&amp;gt;
                            &amp;lt;set token="tok_wimg"&amp;gt;$result.sourcetype$&amp;lt;/set&amp;gt;
                     &amp;lt;/condition&amp;gt;
                     &amp;lt;condition&amp;gt;
                            &amp;lt;set token="tok_wimg"&amp;gt;No result found&amp;lt;/set&amp;gt;
                     &amp;lt;/condition&amp;gt;
          &amp;lt;/finalized &amp;gt;           
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;html&amp;gt;
      &amp;lt;h1&amp;gt;$tok_wimg$&amp;lt;/h1&amp;gt;
    &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The html panel will display the token name just during the execution time since you are setting the token on search finalization. If you do not want to display at all, just hide the panel until search is finished using the tokens.&lt;/P&gt;

&lt;P&gt;See here for details&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.3/Viz/EventHandlerReference#Search_event_handlers"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.3/Viz/EventHandlerReference#Search_event_handlers&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2016 12:13:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232330#M68903</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2016-08-18T12:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a token from a base search in my dashboard to be consumed in an HTML panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232331#M68904</link>
      <description>&lt;P&gt;hi renjith.nair, &lt;/P&gt;

&lt;P&gt;your example works. thanks!&lt;/P&gt;

&lt;P&gt;thanks&lt;BR /&gt;
steve&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2016 12:26:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232331#M68904</guid>
      <dc:creator>swe</dc:creator>
      <dc:date>2016-08-18T12:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a token from a base search in my dashboard to be consumed in an HTML panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232332#M68905</link>
      <description>&lt;P&gt;THANK YOU! I was trying so hard just to wrap text for a SingleElement and messing with so much stuff... this was so much easier. Thank you so much.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 19:16:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232332#M68905</guid>
      <dc:creator>justdaveconsult</dc:creator>
      <dc:date>2019-04-18T19:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a token from a base search in my dashboard to be consumed in an HTML panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232333#M68906</link>
      <description>&lt;P&gt;This is great, thanks a bunch!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 19:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232333#M68906</guid>
      <dc:creator>mmcg</dc:creator>
      <dc:date>2019-04-18T19:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a token from a base search in my dashboard to be consumed in an HTML panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232334#M68907</link>
      <description>&lt;P&gt;How does anybody consider this a valid answer?  The question &lt;EM&gt;specifically&lt;/EM&gt; asks says &lt;CODE&gt;from a base search&lt;/CODE&gt;.  There is no &lt;CODE&gt;base search&lt;/CODE&gt; in this answer.  What am I missing.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 20:40:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/232334#M68907</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-19T20:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to set a token from a base search in my dashboard to be consumed in an HTML panel?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/651980#M225364</link>
      <description>&lt;P&gt;Is there a different method when its on base search?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 19:23:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-set-a-token-from-a-base-search-in-my-dashboard-to-be/m-p/651980#M225364</guid>
      <dc:creator>shalomsuresh</dc:creator>
      <dc:date>2023-07-25T19:23:21Z</dc:date>
    </item>
  </channel>
</rss>

