Dashboards & Visualizations

Dropdow populating, but inactive

norbertt911
Communicator

Hi,

I have a Dasboard for user activity and I would like to add usernames with a dropdown input. 

<fieldset submitButton="true" autoRun="false">
<input type="dropdown" token="user">
<label>Username / Identity</label>
<search>
<query>`umbrella` | stats count by identities | sort + identities | fields - count</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<fieldForLabel>user</fieldForLabel>
<fieldForValue>user</fieldForValue>
</input>

Search results with the user's list.  Rest of the boards  are using  `umbrella` identities="$user$" ... searches (if I add a text input and username manually all working fine)

But... The dropdow input still appears inactive - greyed out and mouse over show red crossed out circle 😞

What I missed? (In other app same thing working fine, naturally I'm admin in this app, so I doubt it's permission)

 

Labels (1)
0 Karma
1 Solution

renjith_nair
Legend

Change the fieldForLabel and fieldForValue to identities  from user

or  rename the identities to user in the populating search

 

 

<fieldset submitButton="true" autoRun="false">
<input type="dropdown" token="user">
<label>Username / Identity</label>
<search>
<query>`umbrella` | stats count by identities | sort + identities | fields - count</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<fieldForLabel>identities</fieldForLabel>
<fieldForValue>identities</fieldForValue>
</input>

 

 

PS: Please use code samples (</>) to paste xml snippets for better readability, edited for you now

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

norbertt911
Communicator

Thank you! #imsonoob 🙂

0 Karma

renjith_nair
Legend

Change the fieldForLabel and fieldForValue to identities  from user

or  rename the identities to user in the populating search

 

 

<fieldset submitButton="true" autoRun="false">
<input type="dropdown" token="user">
<label>Username / Identity</label>
<search>
<query>`umbrella` | stats count by identities | sort + identities | fields - count</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<fieldForLabel>identities</fieldForLabel>
<fieldForValue>identities</fieldForValue>
</input>

 

 

PS: Please use code samples (</>) to paste xml snippets for better readability, edited for you now

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...