Dashboards & Visualizations

How to build a multi-input dashboard and ignore inputs that are left blank?

Glasses
Builder

Hi 

I am trying to build a multi-input textbox dashboard based on a KVstore lookup.

My query is like this

 

| inputlookup <some-host-detail-kvlookup>
| search $computer_name$ OR $computer_number$ OR $computer_id$
| fields computerName computerNumber ComputerId ... 

 

each token has a prefix i.e. <fieldName> =  (which is the column header field in the lookup)

each token also has an initial value = null 

thus the query runs like this 

 

 

| search computerName=null OR computerNumber=null OR ComputerId=null

| search computerName=FOO  OR computerNumber=null OR ComputerId=null

 

 

as you can see setting  the <fieldName> to null allows the search to run without breaking, but after a user enters FOO for the computerName value, they need to reset the blank search inputs back to null.   Otherwise if a blank is passed like 

 

| search computerName= OR computerNumber=null OR ComputerId=null

 

the search breaks.

 

Any suggestions how to ignore the empty inputs or a way to reset the initial values to null again is greatly appreciated.  OR if anyone has a suggestion to do this another way, I would very much like to hear.

Thank you

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...