Dashboards & Visualizations

Dashboard exclude multiple string from input text

newbie09
Explorer

Hello,

My objective is to exclude anything the user input from an input text in a dashboard.

Search string:

index = index_string  sourcetype =  stype_string |eval host = mvindex(fields ,10) | where NOT host in ("$host_token$")

 

Input xml like this:

<input type="text" token="host_token">

<label>Host</label>

<default></default>

</input>

The above works only for a single input in the textbox.

ex.  host1

But if multiple host it doesn't work. Nothing is filtered and all below host shows

ex. host1,host2,host3

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...