Dashboards & Visualizations

How can I apply a dashboard filter that gets its values from a lookup?

andrewtrobec
Motivator

Hello,

I am trying to filter a set dashboard charts with a multiselect token, only that the multiselect values come from a lookup. Here is where I get the values:

index="my_index" | lookup Resources.csv Resource_Name OUTPUT Team | stats values(Team) as Team | mvexpand Team

I have two issues:

  1. I cannot add the token I've created to the search since the lookup values aren't available at the beginning to add as a filter.
  2. Once I have multiple values, I don't know how to set the Prefix and Suffix to allow for all values

What is the recommended command to filter all data at the end according to multiple fields and field values?

Thank you and best regards,

Andrew

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi andrewtrobec,

if I correctly understood: you have to create a multivalue input from a lookup and then use it to filter a search?

if this is your need you have to:

create a multivalue input (called e.g. myToken) from the lookup using something like this

|inputlookup Resources.csv | dedup Team, | sort Team | table Team

putting in:

  • Prefix Team="
  • Suffix "
  • Delimiters " OR Team="

After you can insert in your search

 index="my_index" | lookup Resources.csv Resource_Name OUTPUT Team | search $myToken$ | ...

Bye.
Giuseppe

View solution in original post

andrewtrobec
Motivator

Exactly what I was looking for! Thank you!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi andrewtrobec,

if I correctly understood: you have to create a multivalue input from a lookup and then use it to filter a search?

if this is your need you have to:

create a multivalue input (called e.g. myToken) from the lookup using something like this

|inputlookup Resources.csv | dedup Team, | sort Team | table Team

putting in:

  • Prefix Team="
  • Suffix "
  • Delimiters " OR Team="

After you can insert in your search

 index="my_index" | lookup Resources.csv Resource_Name OUTPUT Team | search $myToken$ | ...

Bye.
Giuseppe

Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...