Dashboards & Visualizations

Dropdown based on another dropdown

sarahw3
Explorer

I have a dropdown menu where you can select a state and I want another dropdown for city. Is there a way that the city dropdown then only has the options for the state chosen? For example, if I chose Massachusetts in the first dropdown, Los Angeles would not be an option to pick on the second drop down menu.

0 Karma
1 Solution

cmerriman
Super Champion

use the token that is creating the state dropdown in your search that is creating the city dropdown.

for instance, if $state$ is the token name for your state dropdown:

  sourcetype="support_csv" location=$state$|stats count by city|fields - count

View solution in original post

0 Karma

sscullion_splun
Splunk Employee
Splunk Employee

What you want is a cascading input.

First input populating search:
sourcetype=mySourcetype | stats count by "State"

First input token: state_token

Second input populating search:
sourcetype=mySourcetype State=$state_token|s$ | stats count by "City"

Note the use of a |s filter with the state_token. This will add quote marks to capture states like North Dakota.

0 Karma

woodcock
Esteemed Legend

Use a populating search for the 2nd dropdown that uses something like |inputcsv YourFileWithStatesAndCities Here | search State=$state$

0 Karma

cmerriman
Super Champion

use the token that is creating the state dropdown in your search that is creating the city dropdown.

for instance, if $state$ is the token name for your state dropdown:

  sourcetype="support_csv" location=$state$|stats count by city|fields - count
0 Karma

sarahw3
Explorer

It is saying my search produces no result. I tried it as State=$state$ and that didn't work either.

0 Karma

sarahw3
Explorer

When I get rid of the part with the token it works but it shows all the cities for all states.

0 Karma

cmerriman
Super Champion

can you paste your xml from your dashboard so i can see what might be happening? i just need the part from <fieldset...> to </fieldset> where all the dropdowns are

0 Karma

sarahw3
Explorer

I got it! I just had to put the token in quotes! Thank you so much for all your help! You are a life saver!! I wish I had all your splunk knowledge hahaha!

0 Karma
Get Updates on the Splunk Community!

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...