lookup contains fileds called arguments and values like
ip=$ip$, location=$location$
ip=$ip$
domain_name=$domain_name$
location=$loaction$
domanin=$domain$ location=$location$
etc
I select $arguments$ from dropdown, search contains $arguments$ token and token values will be values of lookup table, values cantains token like ip, location, domain etc. token value changes based on drop-down selection.
I am getting null in results, without input(ip,location and domain_name etc) splunk running table search
XMl looks like
OneTokenAsValueForAnotherToken
<input type="dropdown" token="arguments">
<label>arguments:</label>
<choice value="*">All</choice>
<search>
<query> |inputlookup lookup_name | table arguments</query>
</search>
<default>*</default>
<fieldForLabel>arguments</fieldForLabel>
<fieldForValue>arguments</fieldForValue>
</input>
<label>ip</label>
<label>location</label>
<input type="text" token="domain_name">
<label>domain_name</label>
<table>
<searchString>index=_internal | table ip, lcation | append [| makeresults | $arguments$ ] | table ip, lcation </searchString>
<earliestTime>-60m@m</earliestTime>
<latestTime>now</latestTime>
</table>
If I understood your question correctly your table search is not working right?
Can you try $form.argument$ instead of $argument$ in your table query?
Sid