Dashboards & Visualizations

Dashboard Studio - Is setting tokens from job results only available in v9?

stucky101
Engager

Hi

I'm trying to save the results of 2 queries on a dash to a token and then add them up into a 3rd query.

I'm running 8.2 and and it's beginning to look like all this only became available in 9 ?

https://docs.splunk.com/Documentation/Splunk/9.0.0/DashStudio/searchTokens

I dont see the button described here

  1. In the Edit Data Source panel, check the box for Use search results or job status as tokens.

 I tried some of the stuff like job.resultCount etc...but cannot get anything to interpolate.

Am I totally out of luck for v8.2 ?

Labels (1)
0 Karma

mpalarchio
Splunk Employee
Splunk Employee

Hi @stucky101 -  you are correct that search tokens are a feature that were just recently added in 9.0, whenever you upgrade to 9.0 or any future releases of Splunk you'll definitely be able to use search tokens in the way you're describing!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...