I am trying to use the fields that are pulled from the SQL database that were enriched with Splunk DB Connect. When creating a dashboard drop-down list I am trying to replace the previous input of user names using " |inputlookup Employees.csv|search name " and instead replace with a search directly from the database itself. Any command to replace the inputlookup? I was thinking just the "|search name " would have worked, but it didn't
You need the dbxquery
command to pull directly from the DB, but depending on how often you will be doing this, I would advise against it. Generally the right thing to do is to use dbxquery | outputlookup
in a daily/hourly/whatever scheduled search and then use |iinputlookup
or |lookup
in your dashboards, reports, and searches.
You need the dbxquery
command to pull directly from the DB, but depending on how often you will be doing this, I would advise against it. Generally the right thing to do is to use dbxquery | outputlookup
in a daily/hourly/whatever scheduled search and then use |iinputlookup
or |lookup
in your dashboards, reports, and searches.