Dashboards & Visualizations

How do you create a Splunk Dashboard input which allows users to select fields to filter and conditions to filter?

rijutha
Explorer

I have a search dashboard to search the KV Store based on a set of fields.

Lets say: FieldA FieldB FieldC FieldD FieldE ... FieldP

The user wants to filter only by FieldA and FieldB with FieldA=12 AND FieldB!=OTHER.

My search query in the panel will be | inputlookup mykv where FieldA=*12* AND

FieldB!=OTHER

If the user wants to filter by FieldE=* AND FieldO=*OTHER*, then my query should change to | inputlookup mykv where FieldE=* AND FieldO=*OTHER*

What I have done is to have drop downs for each field where the user can select if he wants to search by "contains" or "not contains" like below.

The text boxes to enter the string they would want to search on.

The challenge is: how do i consolidate the tokens for all the text boxes that have a value and create by where condition that can be replaced in my table query with a single token that says for e.g., $query$?

Would be great if somebody can help me with this. Thank you in advance.

alt text

alt text

0 Karma

HiroshiSatoh
Champion

Try this!

xml sample
  <fieldset submitButton="false">
    <input type="radio" token="con">
      <label>con</label>
      <choice value="=">contains</choice>
      <choice value="!=">not contains</choice>
    </input>
    <input type="text" token="FieldA">
      <label>FieldA</label>
    </input>
  </fieldset>

search sample
 (your  search) FieldA$con$$FieldA$
0 Karma

rijutha
Explorer

Thanks HiroshiSatoh. How do i do it when I have multiple fields and sometimes the user would filter by fieldA and sometimes by fieldB? and sometimes by both.

0 Karma

HiroshiSatoh
Champion

I think the same is true when using multiple fields, but what's wrong?

(your search) FieldA$con_a$$FieldA$ FieldB$con_b$$FieldB$ FieldC$con_c$$FieldC$

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...