Dashboards & Visualizations

Dashboard set input variables with a token from another input

thefuzz4
Path Finder

I'm in the process of building out a new dashboard that will have 3 input selects.

1. Datetime
2. Input1
3. Input2

Input1 is dependent on Datetime and input2 is dependent on input1. I'm using search strings to set all 3 inputs but I need to have it setup populate the drop downs for input1 and 2. This way everything in the dashboard will only return results for the values that are in the drop downs. I know I can do an earliest latest in my search but I'd rather have input1 derive its data from the datetime selector. I don't see an option in the time selector values to tie it back to a token like when you add a search to a panel.

We're currently on Splunk 7.0.3

Thank you for your assistance.

Tags (1)
0 Karma
1 Solution

CarsonZa
Contributor

when you create a time input there is a field named token. use this token in "input2" or " input3". In the time picker in "input2" go to advanced and enter $token_name.earliest$ and $token_name.latest$ respectively

View solution in original post

CarsonZa
Contributor

when you create a time input there is a field named token. use this token in "input2" or " input3". In the time picker in "input2" go to advanced and enter $token_name.earliest$ and $token_name.latest$ respectively

thefuzz4
Path Finder

You got me on the right path. I wasn't able to put them into the advanced field for the time picker however I did add it to my search to populate the box at the beginning as so: earliest=$datetime.earliest$ latest=$datetime.latest$

Thank you for your help with this.

0 Karma

niketn
Legend

@thefuzz4 for the community to assist you better you would need to add more details on what is not working with sample code of what you have. Unfortunately the description provided in the question seems very high level for us to understand your issue and requirement.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...