Dashboards & Visualizations

Dropdow populating, but inactive

norbertt911
Communicator

Hi,

I have a Dasboard for user activity and I would like to add usernames with a dropdown input. 

<fieldset submitButton="true" autoRun="false">
<input type="dropdown" token="user">
<label>Username / Identity</label>
<search>
<query>`umbrella` | stats count by identities | sort + identities | fields - count</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<fieldForLabel>user</fieldForLabel>
<fieldForValue>user</fieldForValue>
</input>

Search results with the user's list.  Rest of the boards  are using  `umbrella` identities="$user$" ... searches (if I add a text input and username manually all working fine)

But... The dropdow input still appears inactive - greyed out and mouse over show red crossed out circle 😞

What I missed? (In other app same thing working fine, naturally I'm admin in this app, so I doubt it's permission)

 

Labels (2)
0 Karma
1 Solution

renjith_nair
Legend

Change the fieldForLabel and fieldForValue to identities  from user

or  rename the identities to user in the populating search

 

 

<fieldset submitButton="true" autoRun="false">
<input type="dropdown" token="user">
<label>Username / Identity</label>
<search>
<query>`umbrella` | stats count by identities | sort + identities | fields - count</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<fieldForLabel>identities</fieldForLabel>
<fieldForValue>identities</fieldForValue>
</input>

 

 

PS: Please use code samples (</>) to paste xml snippets for better readability, edited for you now

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

norbertt911
Communicator

Thank you! #imsonoob 🙂

0 Karma

renjith_nair
Legend

Change the fieldForLabel and fieldForValue to identities  from user

or  rename the identities to user in the populating search

 

 

<fieldset submitButton="true" autoRun="false">
<input type="dropdown" token="user">
<label>Username / Identity</label>
<search>
<query>`umbrella` | stats count by identities | sort + identities | fields - count</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<fieldForLabel>identities</fieldForLabel>
<fieldForValue>identities</fieldForValue>
</input>

 

 

PS: Please use code samples (</>) to paste xml snippets for better readability, edited for you now

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...