Dashboards & Visualizations

Create a token from every field in a search

mew1033
Explorer

I have a search that I'm using to generate tokens on a dashboard. It only has 1 row, so I'm using `$result.<field>$`. There are a large number of fields, and I want all of them to be tokens. Is there a way I can do that? Maybe with the dashboard eval thing? Using foreach perhaps?

 

Thanks

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Technically speaking, you already have a token for every field - $result.<field>$.

What problem are you trying to solve with so many tokens?

---
If this reply helps you, Karma would be appreciated.
0 Karma

mew1033
Explorer

But wouldn't I have to enclose panels and such that need to use the $result.<field>$ syntax inside of the <search> tags? Can you do that?

 

I'm basically making a dashboard with a whole bunch of these:

mew1033_0-1638306489815.png

I'm injecting the numbers below the percentage via the tokens.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

In that case, you will have to assign each $result.<field>$ you wish to use later to a different token.  There's no shortcut for that, AFAIK.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mew1033
Explorer

Ah, I was afraid of that. Oh well, thought I'd ask.

Thanks for the quick answers!

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...