I am developing a set of Splunk dashboards that will be used by N different teams.
Each team has its own index (say indexA, indexB), and each of those indexes have 2 sources (sourceA1, sourceA2, sourceB1, sourceB2) etc.
All the indexes have exact schema (with different data for different teams) and so I want to have re-usable dashboards.
Which means that in my dashboard, I plan to have a drop-down (single-select), with a list of team names, which under-the-hood map to an index name and two source names. (1 to 3 mapping)
In my panels then I can create searches using those tokens and so the same dashboard will show team A's data or team B's data depending on which team is selected in drop-down.
Since our indexes are access-controlled, if a user from team A chooses team B in dropdown, he will see empty panels which is what is intended.