hello
the values in my dropdown all contain quotes like "Name of App". I can see Splunk needing to escape these quotes in a search with \" but can't figure out how to do this in my dashboard. hope that makes sense.
<input type="dropdown" token="DisplayName" searchWhenChanged="true">
<label>App</label>
<choice value="*">All</choice>
<fieldForLabel>DisplayName</fieldForLabel>
<fieldForValue>DisplayName</fieldForValue>
<search>
<query>index=windows sourcetype=Script:InstalledApps | table DisplayName | dedup DisplayName</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<default>*</default>
</input>
</fieldset>
<row>
<panel>
<table>
<search>
<query>index=windows sourcetype=Script:InstalledApps host=$host$ DisplayName=$DisplayName$
Assuming that the DisplayName field values have embedded space, you can use the s filter to wrap the value in quotes
index=windows sourcetype=Script:InstalledApps host=$host$ DisplayName=$DisplayName|s$