How do I use a token in another token?
I get results from the dashboard, and I put that in org token:
set token="org" $result.org$ set
values= of org is, field1=$name$, filed2=$department$
When I call the org token in a dashboard panel, I am getting a null value.
To set:
<set token="global_org" $result.org$</set>
To access (anywhere except for the search where it is being set):
... The org is $global_org$.
OneTokenAsValueForAnotherToken
<input type="dropdown" token="arguments">
<label>arguments:</label>
<choice value="*">All</choice>
<search>
<query> |inputlookup lookup_name | table arguments</query>
</search>
<default>*</default>
<fieldForLabel>arguments</fieldForLabel>
<fieldForValue>arguments</fieldForValue>
</input>
<label>ip</label>
<label>location</label>
<input type="text" token="domain_name">
<label>domain_name</label>
<table>
<searchString>index=_internal | table ip, lcation | append [| makeresults | $arguments$ ] | table ip, lcation </searchString>
<earliestTime>-60m@m</earliestTime>
<latestTime>now</latestTime>
</table>
OneTokenAsValueForAnotherToken
<input type="dropdown" token="arguments">
<label>arguments:</label>
<choice value="*">All</choice>
<search>
<query> |inputlookup lookup_name | table arguments</query>
</search>
<default>*</default>
<fieldForLabel>arguments</fieldForLabel>
<fieldForValue>arguments</fieldForValue>
</input>
<label>ip</label>
<label>location</label>
<input type="text" token="domain_name">
<label>domain_name</label>
<table>
<searchString>index=_internal | table ip, lcation | append [| makeresults | $arguments$ ] | table ip, lcation </searchString>
<earliestTime>-60m@m</earliestTime>
<latestTime>now</latestTime>
</table>
the above lookup contains fileds called arguments and values like
ip=$ip$, location=$location$
ip=$ip$
domain_name=$domain_name$
location=$loaction$
domanin=$domain$ location=$location$
etc
I select $arguments$ from dropdown, search contains $arguments$ token and token values will be values of lookup table, values cantains token like ip, location, domain etc. token value changes based on drop-down selection.
I am getting null in results, without input(ip,location and domain_name etc) splunk running table search
Try escaping
by using two $
like this $$name$$
.
My question is Like below question
https://answers.splunk.com/answers/138803/set-token-in-the-value-of-another-token.html
but this solution is not working, I am using splunk 7.1
your solution is not working
Your question is poorly phrased. This is not a token in a token
, it is one field's token used in another field's populating search
, which is very different. I will post an appropriate answer now that the question is clearer.
@nagarjuna560,
Is it possible to share the xml part?
Like below question
https://answers.splunk.com/answers/138803/set-token-in-the-value-of-another-token.html
but this solution is not working