Dashboards & Visualizations

Dashboard input dropdown value contains quotes and cant figure out how to escape them

dbagdanoff
Explorer

hello

the values in my dropdown all contain quotes like "Name of App". I can see Splunk needing to escape these quotes in a search with \" but can't figure out how to do this in my dashboard. hope that makes sense.

<input type="dropdown" token="DisplayName" searchWhenChanged="true">
<label>App</label>
<choice value="*">All</choice>
<fieldForLabel>DisplayName</fieldForLabel>
<fieldForValue>DisplayName</fieldForValue>
<search>
<query>index=windows sourcetype=Script:InstalledApps | table DisplayName | dedup DisplayName</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<default>*</default>
</input>
</fieldset>
<row>
<panel>
<table>
<search>
<query>index=windows sourcetype=Script:InstalledApps host=$host$ DisplayName=$DisplayName$

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming that the DisplayName field values have embedded space, you can use the s filter to wrap the value in quotes

index=windows sourcetype=Script:InstalledApps host=$host$ DisplayName=$DisplayName|s$
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...