Dashboards & Visualizations

Dashboard that takes one input(field) and then determines which query to run?

Patrunner
Engager

Anyone have a tip on how to have a token(from field)- and then determine which query to run based on that input? 

For example
(datasources/queries: fruit, meat, vegetable)

Field: banana
->run query for fruit
->display table about banana from said query. 

Struggling with this one- trying to make a dynamic search bar that populates tables based on the input- thus making multiple of my dashboard redundant. Slimming things down. 

Labels (1)
0 Karma

Patrunner
Engager

Thanks for the reply, however Im not quite looking for an alternative solution. Im wondering if this is something splunk is capable of. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Another option perhaps closer to what you seek is to have each input set a token with the appropriate query string.  Then the search will just invoke that token.

For instance, if "banana" is selected, then the input token's <change> element might set a token called $query$ to what is needed to search for fruit.  The <query> element then becomes simply

<query>$query$</query>

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

One approach is to have a separate panel for each search then have the selected token make the appropriate panel appear. 

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...