Dashboards & Visualizations

How can I apply a dashboard filter that gets its values from a lookup?

andrewtrobec
Motivator

Hello,

I am trying to filter a set dashboard charts with a multiselect token, only that the multiselect values come from a lookup. Here is where I get the values:

index="my_index" | lookup Resources.csv Resource_Name OUTPUT Team | stats values(Team) as Team | mvexpand Team

I have two issues:

  1. I cannot add the token I've created to the search since the lookup values aren't available at the beginning to add as a filter.
  2. Once I have multiple values, I don't know how to set the Prefix and Suffix to allow for all values

What is the recommended command to filter all data at the end according to multiple fields and field values?

Thank you and best regards,

Andrew

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi andrewtrobec,

if I correctly understood: you have to create a multivalue input from a lookup and then use it to filter a search?

if this is your need you have to:

create a multivalue input (called e.g. myToken) from the lookup using something like this

|inputlookup Resources.csv | dedup Team, | sort Team | table Team

putting in:

  • Prefix Team="
  • Suffix "
  • Delimiters " OR Team="

After you can insert in your search

 index="my_index" | lookup Resources.csv Resource_Name OUTPUT Team | search $myToken$ | ...

Bye.
Giuseppe

View solution in original post

andrewtrobec
Motivator

Exactly what I was looking for! Thank you!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi andrewtrobec,

if I correctly understood: you have to create a multivalue input from a lookup and then use it to filter a search?

if this is your need you have to:

create a multivalue input (called e.g. myToken) from the lookup using something like this

|inputlookup Resources.csv | dedup Team, | sort Team | table Team

putting in:

  • Prefix Team="
  • Suffix "
  • Delimiters " OR Team="

After you can insert in your search

 index="my_index" | lookup Resources.csv Resource_Name OUTPUT Team | search $myToken$ | ...

Bye.
Giuseppe

Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...