Dashboards & Visualizations

Dashboard Studio Dynamic Dropdown Input - Query Types

shocko
Contributor

Using Splunk Enterprise 9. I'm trying to populate a dashboard studio dropdown input from query results. I was testing via a simple query (copied from the dashboard studio examples) as follows:

 

| inputlookup firewall_example.csv
| stats count by host

 

This works fine and the dropdown gets populated with the hosts. However, I'd also expected the following to to work 

 

| inputlookup firewall_example.csv
| stats values(host)

 

but it doesn't and no dynamic entries are in the dropdown. 

So my understanding of the query types that can be used with dropdown inputs is incomplete! Can someone point me in the right direction? 

 

 

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

stats values(host) will give you a multi-value field i.e. a single event, whereas, in order to dynamically populate the dropdown, you need separate events (which is what stats count by host does for you).

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

stats values(host) will give you a multi-value field i.e. a single event, whereas, in order to dynamically populate the dropdown, you need separate events (which is what stats count by host does for you).

shocko
Contributor

Thanks for taking the time to reply @ITWhisperer . Much appreciated. That makes perfect sense. 

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...