Dashboards & Visualizations

Dropdown not populating

shaoli21
New Member

| djquery -database ad -query "select short_description from bu_projectdetails order by [order]"

this is the given query........when I am replacing this with lookup files, although result is coming in the search but not in the dropdown.

| inputlookup bu_projectdetails_lookup.csv |table short_description|sort by [order]

alt text

Tags (2)
0 Karma

somesoni2
Revered Legend

Try this for you search.

| inputlookup bu_projectdetails_lookup.csv |table short_description|sort short_description
0 Karma

shaoli21
New Member

its showing the same thing, "could not create search"

0 Karma

vnravikumar
Champion

if possible can you post your xml?

0 Karma

shaoli21
New Member
    <label>Milestones</label>
    <choice value="*">All</choice>
    <search>
      <query>| djquery -database ad -query "select short_description from bu_projectdetails order by [order]"</query>
    </search>
    <fieldForLabel>short_description</fieldForLabel>
    <fieldForValue>short_description</fieldForValue>
    <default>*</default>
    <valuePrefix>short_description="</valuePrefix>
    <valueSuffix>"</valueSuffix>
    <delimiter> OR </delimiter>
  </input>
0 Karma

493669
Super Champion

@shaoli21, did you tried below-

<label>Milestones</label>
     <choice value="*">All</choice>
     <search>
       <query>| inputlookup bu_projectdetails_lookup.csv |table short_description|sort short_description</query>
     </search>
     <fieldForLabel>short_description</fieldForLabel>
     <fieldForValue>short_description</fieldForValue>
     <default>*</default>
     <valuePrefix>short_description="</valuePrefix>
     <valueSuffix>"</valueSuffix>
     <delimiter> OR </delimiter>
   </input>
0 Karma

nickhills
Ultra Champion

oh yeah, missed that 🙂

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

Have you set

<fieldForLabel>short_description</fieldForLabel>
<fieldForValue>short_description</fieldForValue>

In the dropdown settings?

If my comment helps, please give it a thumbs up!
0 Karma

shaoli21
New Member

yes I had set them but still no output

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...