Dashboards & Visualizations

Dashboard set input variables with a token from another input

thefuzz4
Path Finder

I'm in the process of building out a new dashboard that will have 3 input selects.

1. Datetime
2. Input1
3. Input2

Input1 is dependent on Datetime and input2 is dependent on input1. I'm using search strings to set all 3 inputs but I need to have it setup populate the drop downs for input1 and 2. This way everything in the dashboard will only return results for the values that are in the drop downs. I know I can do an earliest latest in my search but I'd rather have input1 derive its data from the datetime selector. I don't see an option in the time selector values to tie it back to a token like when you add a search to a panel.

We're currently on Splunk 7.0.3

Thank you for your assistance.

Tags (1)
0 Karma
1 Solution

CarsonZa
Contributor

when you create a time input there is a field named token. use this token in "input2" or " input3". In the time picker in "input2" go to advanced and enter $token_name.earliest$ and $token_name.latest$ respectively

View solution in original post

CarsonZa
Contributor

when you create a time input there is a field named token. use this token in "input2" or " input3". In the time picker in "input2" go to advanced and enter $token_name.earliest$ and $token_name.latest$ respectively

thefuzz4
Path Finder

You got me on the right path. I wasn't able to put them into the advanced field for the time picker however I did add it to my search to populate the box at the beginning as so: earliest=$datetime.earliest$ latest=$datetime.latest$

Thank you for your help with this.

0 Karma

niketn
Legend

@thefuzz4 for the community to assist you better you would need to add more details on what is not working with sample code of what you have. Unfortunately the description provided in the question seems very high level for us to understand your issue and requirement.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...