Dashboards & Visualizations

How do you create a Splunk Dashboard input which allows users to select fields to filter and conditions to filter?

rijutha
Explorer

I have a search dashboard to search the KV Store based on a set of fields.

Lets say: FieldA FieldB FieldC FieldD FieldE ... FieldP

The user wants to filter only by FieldA and FieldB with FieldA=12 AND FieldB!=OTHER.

My search query in the panel will be | inputlookup mykv where FieldA=*12* AND

FieldB!=OTHER

If the user wants to filter by FieldE=* AND FieldO=*OTHER*, then my query should change to | inputlookup mykv where FieldE=* AND FieldO=*OTHER*

What I have done is to have drop downs for each field where the user can select if he wants to search by "contains" or "not contains" like below.

The text boxes to enter the string they would want to search on.

The challenge is: how do i consolidate the tokens for all the text boxes that have a value and create by where condition that can be replaced in my table query with a single token that says for e.g., $query$?

Would be great if somebody can help me with this. Thank you in advance.

alt text

alt text

0 Karma

HiroshiSatoh
Champion

Try this!

xml sample
  <fieldset submitButton="false">
    <input type="radio" token="con">
      <label>con</label>
      <choice value="=">contains</choice>
      <choice value="!=">not contains</choice>
    </input>
    <input type="text" token="FieldA">
      <label>FieldA</label>
    </input>
  </fieldset>

search sample
 (your  search) FieldA$con$$FieldA$
0 Karma

rijutha
Explorer

Thanks HiroshiSatoh. How do i do it when I have multiple fields and sometimes the user would filter by fieldA and sometimes by fieldB? and sometimes by both.

0 Karma

HiroshiSatoh
Champion

I think the same is true when using multiple fields, but what's wrong?

(your search) FieldA$con_a$$FieldA$ FieldB$con_b$$FieldB$ FieldC$con_c$$FieldC$

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...