Dashboards & Visualizations

Dropdow populating, but inactive

norbertt911
Communicator

Hi,

I have a Dasboard for user activity and I would like to add usernames with a dropdown input. 

<fieldset submitButton="true" autoRun="false">
<input type="dropdown" token="user">
<label>Username / Identity</label>
<search>
<query>`umbrella` | stats count by identities | sort + identities | fields - count</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<fieldForLabel>user</fieldForLabel>
<fieldForValue>user</fieldForValue>
</input>

Search results with the user's list.  Rest of the boards  are using  `umbrella` identities="$user$" ... searches (if I add a text input and username manually all working fine)

But... The dropdow input still appears inactive - greyed out and mouse over show red crossed out circle 😞

What I missed? (In other app same thing working fine, naturally I'm admin in this app, so I doubt it's permission)

 

Labels (2)
0 Karma
1 Solution

renjith_nair
Legend

Change the fieldForLabel and fieldForValue to identities  from user

or  rename the identities to user in the populating search

 

 

<fieldset submitButton="true" autoRun="false">
<input type="dropdown" token="user">
<label>Username / Identity</label>
<search>
<query>`umbrella` | stats count by identities | sort + identities | fields - count</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<fieldForLabel>identities</fieldForLabel>
<fieldForValue>identities</fieldForValue>
</input>

 

 

PS: Please use code samples (</>) to paste xml snippets for better readability, edited for you now

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

norbertt911
Communicator

Thank you! #imsonoob 🙂

0 Karma

renjith_nair
Legend

Change the fieldForLabel and fieldForValue to identities  from user

or  rename the identities to user in the populating search

 

 

<fieldset submitButton="true" autoRun="false">
<input type="dropdown" token="user">
<label>Username / Identity</label>
<search>
<query>`umbrella` | stats count by identities | sort + identities | fields - count</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<fieldForLabel>identities</fieldForLabel>
<fieldForValue>identities</fieldForValue>
</input>

 

 

PS: Please use code samples (</>) to paste xml snippets for better readability, edited for you now

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...