Security

Form error when referencing a token in the search

cbbrown
New Member

I have three multi-selection options for my form. All three default to *, but the main panel of the form throws an error when I reference one or all of the token values to filter the search down. I get the following error: Error in 'search' command unable to parse the search: Comparator '=' has an invalid term on the right hand side.

The search string for the panel calling the token is as follows:

| dbxquery output='csv' connection="blah" query="SELECT * FROM "blah_data"
| search filtering_field=$filter_tok$
| table field1 field2 field3

The Multi-selection input is defined as follows:

Label: Filtering Field
Token Options
Token: filter_tok
Default: All
Token Prefix: (
Token Suffix: )
Token Value Prefix: Filtering_Field="
Token Value Suffix= "
Delimiter: OR (spaces before and after OR)
Static Options
Name: All
Value: *

Dynamic Options
Search String:
| dbxquery output='csv' connection="blah" query="SELECT * FROM "blah_data"
| dedup filtering_field
| table filtering_field

Time Input: Last 24 Hours
Field For Label: Filtering_Field
Field of Value: Filtering_Field

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...