Dashboards & Visualizations

Dashboard with a partial search bar

lsbarreto96
Engager

Hello All,

I am trying  to create a dashboard with an interactive input search bar. The field that is searchable has always 16 digits but I want the users to only search with the 6 first digits, for example they will inform a number 123456, and whatever occurrence with the "123456" will show in the report.

I tried to use the sufix field, putting an "*" but it failed, I also tried to include the "*" in the search with the token but it also failed.

Is there any way to do it?

 

Thank you in a dvancne!

Labels (2)
0 Karma
1 Solution

venkatasri
SplunkTrust
SplunkTrust

Hi @lsbarreto96 

I assume you are using Splunk classic simple xml style dashboard, I have tested following and it works with suffix. Can you compare with source code if this works?

 

<form>
  <label>Test</label>
  <fieldset submitButton="false">
    <input type="text" token="token_name">
      <label>Field Name</label>
      <suffix>*</suffix>
    </input>
  </fieldset>
  <row>
    <panel>
      <table>
        <search>
          <query>index=_internal sourcetype=$token_name$</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
      </table>
    </panel>
  </row>
</form>

 

---

An upvote would be appreciated and Accept solution if this reply helps!

View solution in original post

venkatasri
SplunkTrust
SplunkTrust

Hi @lsbarreto96 

I assume you are using Splunk classic simple xml style dashboard, I have tested following and it works with suffix. Can you compare with source code if this works?

 

<form>
  <label>Test</label>
  <fieldset submitButton="false">
    <input type="text" token="token_name">
      <label>Field Name</label>
      <suffix>*</suffix>
    </input>
  </fieldset>
  <row>
    <panel>
      <table>
        <search>
          <query>index=_internal sourcetype=$token_name$</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
      </table>
    </panel>
  </row>
</form>

 

---

An upvote would be appreciated and Accept solution if this reply helps!

lsbarreto96
Engager

Thank you very  much! It has worked now! 

0 Karma

venkatasri
SplunkTrust
SplunkTrust

@lsbarreto96 glad it helped. It would be great if you could accept the solution it helps others.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...