I have a very simple dynamic dropdown that lists computers by their FQDN. I have one panel that can use that token value "Failures" and I have one panel that needs the domain name stripped away "Errors." Is there an easy way to do this?
<fieldset submitButton="false" autoRun="true">
<input type="dropdown" token="TheName">
<label>Computers:</label>
<fieldForLabel>host</fieldForLabel>
<fieldForValue>host</fieldForValue>
<search>
<query>index="bfront" source="/var/log/audit/audit.log" | dedup host | table host | sort by host</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
</input>
<input type="time" token="TheTime" depends="$TheName$">
<label>Time:</label>
<default>
<earliest>-7d@h</earliest>
<latest>now</latest>
</default>
</input>
</fieldset>
<row>
<panel depends="$TheName$">
<title>Failures</title>
<chart>
<search>
<query>index="bfront" sourcetype="linux_audit" host="$TheName$" type=USER_LOGIN res=failed | top limit=10 acct</query>
<earliest>$TheTime.earliest$</earliest>
<latest>$TheTime.latest$</latest>
<refresh>5m</refresh>
<refreshType>delay</refreshType>
</search>
<option name="charting.axisTitleX.visibility">collapsed</option>
<option name="charting.axisTitleY.visibility">collapsed</option>
<option name="charting.axisY.abbreviation">none</option>
<option name="charting.axisY.scale">linear</option>
<option name="charting.chart">bar</option>
<option name="charting.chart.showDataLabels">all</option>
<option name="charting.drilldown">all</option>
<option name="charting.layout.splitSeries">0</option>
<option name="charting.legend.placement">none</option>
<option name="charting.seriesColors">["0xf8be34","0xf8be34","0xf8be34","0xf8be34","0xf8be34"]</option>
<option name="height">260</option>
<option name="refresh.display">none</option>
</chart>
</panel>
<panel depends="$TheName$">
<title>Errors</title>
<chart>
<search>
<query> index="bront" source="/var/log/messages" host="$TheName$" eventtype=err0r | top limit=20 process</query>
<earliest>$TheTime.earliest$</earliest>
<latest>$TheTime.latest$</latest>
<refresh>5m</refresh>
<refreshType>delay</refreshType>
</search>
<option name="charting.chart">pie</option>
<option name="charting.drilldown">all</option>
<option name="height">270</option>
<option name="refresh.display">none</option>
</chart>
</panel>
</row>
Evaluate smallhost as everything before the first dot in host and use this as the label, keeping the fqdn as the value. Then set tokens for use in queries when the dropdown changes.
<fieldset submitButton="false" autoRun="true">
<input type="dropdown" token="TheName">
<label>Computers:</label>
<fieldForLabel>smallhost</fieldForLabel>
<fieldForValue>host</fieldForValue>
<search>
<query>index="bfront" source="/var/log/audit/audit.log" | dedup host | table host | sort by host | rex field=host "^(?<smallhost>[^\.]+)"</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<change>
<set token="failhost">$value$</set>
<set token="errorhost">$label$</set>
</change>
</input>
<input type="time" token="TheTime" depends="$TheName$">
<label>Time:</label>
<default>
<earliest>-7d@h</earliest>
<latest>now</latest>
</default>
</input>
</fieldset>
<row>
<panel depends="$TheName$">
<title>Failures</title>
<chart>
<search>
<query>index="bfront" sourcetype="linux_audit" host="$failhost$" type=USER_LOGIN res=failed | top limit=10 acct</query>
<earliest>$TheTime.earliest$</earliest>
<latest>$TheTime.latest$</latest>
<refresh>5m</refresh>
<refreshType>delay</refreshType>
</search>
<option name="charting.axisTitleX.visibility">collapsed</option>
<option name="charting.axisTitleY.visibility">collapsed</option>
<option name="charting.axisY.abbreviation">none</option>
<option name="charting.axisY.scale">linear</option>
<option name="charting.chart">bar</option>
<option name="charting.chart.showDataLabels">all</option>
<option name="charting.drilldown">all</option>
<option name="charting.layout.splitSeries">0</option>
<option name="charting.legend.placement">none</option>
<option name="charting.seriesColors">["0xf8be34","0xf8be34","0xf8be34","0xf8be34","0xf8be34"]</option>
<option name="height">260</option>
<option name="refresh.display">none</option>
</chart>
</panel>
<panel depends="$TheName$">
<title>Errors</title>
<chart>
<search>
<query> index="bront" source="/var/log/messages" host="$errorhost$" eventtype=err0r | top limit=20 process</query>
<earliest>$TheTime.earliest$</earliest>
<latest>$TheTime.latest$</latest>
<refresh>5m</refresh>
<refreshType>delay</refreshType>
</search>
<option name="charting.chart">pie</option>
<option name="charting.drilldown">all</option>
<option name="height">270</option>
<option name="refresh.display">none</option>
</chart>
</panel>
</row>
Evaluate smallhost as everything before the first dot in host and use this as the label, keeping the fqdn as the value. Then set tokens for use in queries when the dropdown changes.
<fieldset submitButton="false" autoRun="true">
<input type="dropdown" token="TheName">
<label>Computers:</label>
<fieldForLabel>smallhost</fieldForLabel>
<fieldForValue>host</fieldForValue>
<search>
<query>index="bfront" source="/var/log/audit/audit.log" | dedup host | table host | sort by host | rex field=host "^(?<smallhost>[^\.]+)"</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<change>
<set token="failhost">$value$</set>
<set token="errorhost">$label$</set>
</change>
</input>
<input type="time" token="TheTime" depends="$TheName$">
<label>Time:</label>
<default>
<earliest>-7d@h</earliest>
<latest>now</latest>
</default>
</input>
</fieldset>
<row>
<panel depends="$TheName$">
<title>Failures</title>
<chart>
<search>
<query>index="bfront" sourcetype="linux_audit" host="$failhost$" type=USER_LOGIN res=failed | top limit=10 acct</query>
<earliest>$TheTime.earliest$</earliest>
<latest>$TheTime.latest$</latest>
<refresh>5m</refresh>
<refreshType>delay</refreshType>
</search>
<option name="charting.axisTitleX.visibility">collapsed</option>
<option name="charting.axisTitleY.visibility">collapsed</option>
<option name="charting.axisY.abbreviation">none</option>
<option name="charting.axisY.scale">linear</option>
<option name="charting.chart">bar</option>
<option name="charting.chart.showDataLabels">all</option>
<option name="charting.drilldown">all</option>
<option name="charting.layout.splitSeries">0</option>
<option name="charting.legend.placement">none</option>
<option name="charting.seriesColors">["0xf8be34","0xf8be34","0xf8be34","0xf8be34","0xf8be34"]</option>
<option name="height">260</option>
<option name="refresh.display">none</option>
</chart>
</panel>
<panel depends="$TheName$">
<title>Errors</title>
<chart>
<search>
<query> index="bront" source="/var/log/messages" host="$errorhost$" eventtype=err0r | top limit=20 process</query>
<earliest>$TheTime.earliest$</earliest>
<latest>$TheTime.latest$</latest>
<refresh>5m</refresh>
<refreshType>delay</refreshType>
</search>
<option name="charting.chart">pie</option>
<option name="charting.drilldown">all</option>
<option name="height">270</option>
<option name="refresh.display">none</option>
</chart>
</panel>
</row>
This works perfectly! Thanks!!