<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I use tokens in a stats function? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-use-tokens-in-a-stats-function/m-p/236572#M70288</link>
    <description>&lt;P&gt;hi, &lt;/P&gt;

&lt;P&gt;it's possible, &lt;BR /&gt;
try like this with that  example using Dropdown&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &amp;lt;form&amp;gt;

&amp;lt;fieldset&amp;gt;

 &amp;lt;input type="time" token="field1"&amp;gt;
   &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
   &amp;lt;default&amp;gt;
     &amp;lt;earliest&amp;gt;0&amp;lt;/earliest&amp;gt;
     &amp;lt;latest&amp;gt;&amp;lt;/latest&amp;gt;
   &amp;lt;/default&amp;gt;
 &amp;lt;/input&amp;gt;

&amp;lt;input type="dropdown" token="user" searchWhenChanged="true"&amp;gt;
   &amp;lt;label&amp;gt;Select  a sourcetype:&amp;lt;/label&amp;gt;
   &amp;lt;choice value="*"&amp;gt;ALL&amp;lt;/choice&amp;gt;
   &amp;lt;choice value="splunkd"&amp;gt;splunkd&amp;lt;/choice&amp;gt;
   &amp;lt;choice value="audittrail"&amp;gt;audittrail&amp;lt;/choice&amp;gt;
   &amp;lt;choice value="scheduler"&amp;gt;scheduler&amp;lt;/choice&amp;gt;
   &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
 &amp;lt;/input&amp;gt;

 &amp;lt;/fieldset&amp;gt;

&amp;lt;row&amp;gt; 
 &amp;lt;panel&amp;gt;
   &amp;lt;event&amp;gt;
     &amp;lt;search&amp;gt;
       &amp;lt;query&amp;gt;index=* OR index=_* |stats dc($user$) by source&amp;lt;/query&amp;gt;
       &amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;
       &amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;
     &amp;lt;/search&amp;gt;
     &amp;lt;option name="list.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
     &amp;lt;option name="list.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
     &amp;lt;option name="maxLines"&amp;gt;5&amp;lt;/option&amp;gt;
     &amp;lt;option name="raw.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
     &amp;lt;option name="rowNumbers"&amp;gt;0&amp;lt;/option&amp;gt;
     &amp;lt;option name="table.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
     &amp;lt;option name="table.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
     &amp;lt;option name="type"&amp;gt;list&amp;lt;/option&amp;gt;
     &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
     &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
     &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
     &amp;lt;fields&amp;gt;["host","source","sourcetype"]&amp;lt;/fields&amp;gt;
   &amp;lt;/event&amp;gt;
 &amp;lt;/panel&amp;gt;
&amp;lt;/row&amp;gt;
 &amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;please forgive my english.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Mar 2016 09:08:42 GMT</pubDate>
    <dc:creator>gyslainlatsa</dc:creator>
    <dc:date>2016-03-09T09:08:42Z</dc:date>
    <item>
      <title>How can I use tokens in a stats function?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-use-tokens-in-a-stats-function/m-p/236569#M70285</link>
      <description>&lt;P&gt;I want to use a dropdown to change the field that the stats command function uses in calcuation. my token is called my_token.&lt;/P&gt;

&lt;P&gt;example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=myindex mysearch | stats dc($my_token$) by mylocation
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is this possible?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2016 21:22:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-use-tokens-in-a-stats-function/m-p/236569#M70285</guid>
      <dc:creator>jedatt01</dc:creator>
      <dc:date>2016-03-08T21:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: How can I use tokens in a stats function?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-use-tokens-in-a-stats-function/m-p/236570#M70286</link>
      <description>&lt;P&gt;Short answer: yes.&lt;/P&gt;

&lt;P&gt;Tokens are string-replaced before the search is run, you can use them anywhere in your search.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2016 21:48:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-use-tokens-in-a-stats-function/m-p/236570#M70286</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-03-08T21:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: How can I use tokens in a stats function?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-use-tokens-in-a-stats-function/m-p/236571#M70287</link>
      <description>&lt;P&gt;If your token value has spaces in it.&lt;/P&gt;

&lt;P&gt;Example: "this is the token value"&lt;/P&gt;

&lt;P&gt;Then you'll want to put quotes around the token in your stats command.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2016 21:56:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-use-tokens-in-a-stats-function/m-p/236571#M70287</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-03-08T21:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: How can I use tokens in a stats function?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-use-tokens-in-a-stats-function/m-p/236572#M70288</link>
      <description>&lt;P&gt;hi, &lt;/P&gt;

&lt;P&gt;it's possible, &lt;BR /&gt;
try like this with that  example using Dropdown&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &amp;lt;form&amp;gt;

&amp;lt;fieldset&amp;gt;

 &amp;lt;input type="time" token="field1"&amp;gt;
   &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
   &amp;lt;default&amp;gt;
     &amp;lt;earliest&amp;gt;0&amp;lt;/earliest&amp;gt;
     &amp;lt;latest&amp;gt;&amp;lt;/latest&amp;gt;
   &amp;lt;/default&amp;gt;
 &amp;lt;/input&amp;gt;

&amp;lt;input type="dropdown" token="user" searchWhenChanged="true"&amp;gt;
   &amp;lt;label&amp;gt;Select  a sourcetype:&amp;lt;/label&amp;gt;
   &amp;lt;choice value="*"&amp;gt;ALL&amp;lt;/choice&amp;gt;
   &amp;lt;choice value="splunkd"&amp;gt;splunkd&amp;lt;/choice&amp;gt;
   &amp;lt;choice value="audittrail"&amp;gt;audittrail&amp;lt;/choice&amp;gt;
   &amp;lt;choice value="scheduler"&amp;gt;scheduler&amp;lt;/choice&amp;gt;
   &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
 &amp;lt;/input&amp;gt;

 &amp;lt;/fieldset&amp;gt;

&amp;lt;row&amp;gt; 
 &amp;lt;panel&amp;gt;
   &amp;lt;event&amp;gt;
     &amp;lt;search&amp;gt;
       &amp;lt;query&amp;gt;index=* OR index=_* |stats dc($user$) by source&amp;lt;/query&amp;gt;
       &amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;
       &amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;
     &amp;lt;/search&amp;gt;
     &amp;lt;option name="list.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
     &amp;lt;option name="list.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
     &amp;lt;option name="maxLines"&amp;gt;5&amp;lt;/option&amp;gt;
     &amp;lt;option name="raw.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
     &amp;lt;option name="rowNumbers"&amp;gt;0&amp;lt;/option&amp;gt;
     &amp;lt;option name="table.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
     &amp;lt;option name="table.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
     &amp;lt;option name="type"&amp;gt;list&amp;lt;/option&amp;gt;
     &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
     &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
     &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
     &amp;lt;fields&amp;gt;["host","source","sourcetype"]&amp;lt;/fields&amp;gt;
   &amp;lt;/event&amp;gt;
 &amp;lt;/panel&amp;gt;
&amp;lt;/row&amp;gt;
 &amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;please forgive my english.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 09:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-use-tokens-in-a-stats-function/m-p/236572#M70288</guid>
      <dc:creator>gyslainlatsa</dc:creator>
      <dc:date>2016-03-09T09:08:42Z</dc:date>
    </item>
  </channel>
</rss>

