Dashboards & Visualizations

Help for using token filters in a scheduled search

Contributor

Hello

 

I use token filters in a table panel of my dashboard in order to filter the results of the search and it works perfectly when the search is directly filled in the table panel

But I need to use a scheduled search for this monitoring

If I keep the filters in the search, the search doesn't works....

So I put the filters after the loadjob command like below :

Is it correct or not?

 

 

<row>
    <panel>
      <title>Reboot &amp; logon</title>
      <input type="text" token="tok_filterhost" searchWhenChanged="true">
        <label>Hostname</label>
        <default>*</default>
        <initialValue>*</initialValue>
      </input>
      <input type="text" token="tok_filtermodel" searchWhenChanged="true">
        <label>Model.</label>
        <default>*</default>
        <initialValue>*</initialValue>
      </input>
      <input type="text" token="tok_filterbuilding" searchWhenChanged="true">
        <label>Building.</label>
        <default>*</default>
        <initialValue>*</initialValue>
      </input>
      <input type="text" token="tok_reboot" searchWhenChanged="true">
        <label>Days without reboot</label>
        <default>=*</default>
        <initialValue>*</initialValue>
      </input>
      <input type="text" token="tok_logon" searchWhenChanged="true">
        <label>Days without logon</label>
        <default>=*</default>
        <initialValue>*</initialValue>
      </input>
      <table>
        <title>TUTU</title>
        <search>
          <query>| loadjob savedsearch="admin:TOTO_sh:TITI" 
| search Site=$tok_filtersite|s$ 
| search Responsible=$tok_filterresponsible$ 
| search Department=$tok_filterdepartment$ 
| search "Days without logon"$tok_logon$ 
| search "Days without reboot"$tok_reboot$ 
| search Hostname=$tok_filterhost$ 
| search Model=$tok_filtermodel$ 
| search Building=$tok_filterbuilding$</query>

 For more information, here is the stats command done on "TITI" search :

| stats last(BUILDING_CODE) as Building, last(DESCRIPTION_MODEL) as Model, last(LastReboot) as "Last reboot date" last(NbDaysReboot) as "Days without reboot" last(LastLogon) as "Last logon date" last(NbDaysLogon) as "Days without logon" by host SITE RESPONSIBLE_USER DEPARTMENT
| rename host as Hostname, SITE as Site, RESPONSIBLE_USER as Responsible, DEPARTMENT as Department 
| sort -"Days without reboot" -"Days without logon"

Thanks for your help please

Labels (1)
Tags (1)
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!