All Apps and Add-ons

unable to use $foo$ variable in hiddenchartformater

sbsbb
Builder

I'm unable to use $foo$ variable in hiddenchartformater, I get an error message on saving the view, why ?

Error :

ERROR - $chartType$ is not allowed as a value for chart. Set one of the allowed values - (area, bar, column, line, pie, scatter) or leave it blank.

1 Solution

sideview
SplunkTrust
SplunkTrust

HiddenChartFormatter is a Splunk module not a Sideview module. Sideview modules have params that almost universally interpret $foo$ tokens, whereas in the Splunk modules there are only a couple params in a couple modules.

1) If you're setting chartType from an upstream form element, you dont actually need to filter it through a HiddenChartFormatter. Just change the name of your Pulldown/Radio module from <param name="name">chartType</param> to <param name="name">charting.chart.chartType</param> and delete the problematic line from HiddenChartFormatter entirely.

2) If you have a complex and unusual use case, and ssuming you're on a reasonably current Sideview Utils version, you can replace HiddenChartFormatter with ValueSetter.

<module name="ValueSetter">
  <param name="arg.charting.chart.chartType">$chartType$</param>

and ValueSetter can do more complex things like only overwrite upstream values if other keys are set, or set according to conditional statement testing other keys against values.

If for some reason you're still using the old LGPL version (1.3.5), you should upgrade to latest (3.1.1) Here are release notes so you can see what you're missing.

http://sideviewapps.com/apps/sideview-utils/release-notes/

and here's the licensing FAQ to reassure you that the current version is as free for internal use as the old LGPL version.

http://sideviewapps.com/apps/sideview-utils/licensing-faq/

View solution in original post

sideview
SplunkTrust
SplunkTrust

HiddenChartFormatter is a Splunk module not a Sideview module. Sideview modules have params that almost universally interpret $foo$ tokens, whereas in the Splunk modules there are only a couple params in a couple modules.

1) If you're setting chartType from an upstream form element, you dont actually need to filter it through a HiddenChartFormatter. Just change the name of your Pulldown/Radio module from <param name="name">chartType</param> to <param name="name">charting.chart.chartType</param> and delete the problematic line from HiddenChartFormatter entirely.

2) If you have a complex and unusual use case, and ssuming you're on a reasonably current Sideview Utils version, you can replace HiddenChartFormatter with ValueSetter.

<module name="ValueSetter">
  <param name="arg.charting.chart.chartType">$chartType$</param>

and ValueSetter can do more complex things like only overwrite upstream values if other keys are set, or set according to conditional statement testing other keys against values.

If for some reason you're still using the old LGPL version (1.3.5), you should upgrade to latest (3.1.1) Here are release notes so you can see what you're missing.

http://sideviewapps.com/apps/sideview-utils/release-notes/

and here's the licensing FAQ to reassure you that the current version is as free for internal use as the old LGPL version.

http://sideviewapps.com/apps/sideview-utils/licensing-faq/

richgalloway
SplunkTrust
SplunkTrust

It would seem you're trying to use a variable where one is not allowed. Can you share your XML?

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What is the error message?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...