Dashboards & Visualizations

How to achieve dynamic dropdown all option?

Aroot002
Path Finder

So I've searched and searched but can't seem to find an answer to my issue. I need to add an all option to my dynamic dropdown. I have found answers that seem like they should be simple enough. Either add All, * to static or alter the XML code. I've tried both, (I think when I altered the XML code it pretty much caused the dropdown to be the exact same way as it was had I just added the options to the static section) and each time I am getting a "search string cannot be empty" error. Don't know if it matters but I did watch a couple youtube videos, their search used | table fieldname | dedup fieldname at the end, when I did that I got the same issue, but now all the field values are grouped together, so I'm doing | stats count by fieldname at the end

Labels (2)
0 Karma
1 Solution

johnhuang
Motivator

This is how I would typically configure it:

johnhua_0-1666640560928.png

 

View solution in original post

0 Karma

johnhuang
Motivator

This is how I would typically configure it:

johnhua_0-1666640560928.png

 

0 Karma

Aroot002
Path Finder

Same issue, says that it's ignoring search expansion due to error "search string cannot be empty"

0 Karma

johnhuang
Motivator

Could you click on the magnifying glass to "Open in search" and provide the query?

0 Karma

Aroot002
Path Finder

I'm actually working on my other computer, but I did click the glass, I got the same error when the search opened, could this be more of a log issue? I actually swapped it out for another field and did not get the error.

0 Karma

johnhuang
Motivator

I think it's more of a query issue - could you provide a sample of the query when open to a new search?

0 Karma

Aroot002
Path Finder

I actually just did a simple search to test it out. index=index_name source_type=windows fieldname=* and that got the error. Also tried with quotation marks. But if I change the fieldname to a different one I don't get that error. I don't have a lot of experience in this so I immediately assumed it was something I am doing.

0 Karma

johnhuang
Motivator

Just to confirm,

You ran:

index=index_name source_type=windows fieldname=*

and got an error "search string cannot be empty"? 

0 Karma

Aroot002
Path Finder

Yes, the error is "Ignoring fieldname "value1" for search expansion due to error="search string cannot be empty"

"Ignoring fieldname "value2" for search expansion due to error="search string cannot be empty"

0 Karma

johnhuang
Motivator

If possible, could you provide a screenshot.

0 Karma

Aroot002
Path Finder

I'm actually accepting your first response as a solution... essentially your answer was the correct one. My problem was being caused by an underlying issue with the logs I am querying.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...