Dashboards & Visualizations

How to concatenate multiple tokens and set the combined token in drilldown for automatic search

mandlikarbaaz
Loves-to-Learn Everything

Hi,

I have a requirement to perform end to search for troubleshooting in a dashboard.

I am using multiple tokens inside the dashboard.

Some tokens have a condition to be set or unset depending upon null values.

However, if any of the tokens are not null, then I should concatenate the tokens and pass the combined token to the other sub searches.

Note: There is always a token which is not null

I tried but the other panels always say 'search is waiting for the input'

Below is a sample snippet from the xml dashboard.

<search><query>index=foo</query></search>

<drilldown>

<eval "combined">$token1$. .$token2$. .$token3$. .$token4$. $token5$</eval>

<set "combined_token">$combined$</set>

</drilldown>



<panel>

<search><query>index=abc $combined_token$</query></search>

</panel>
Labels (3)
0 Karma

dural_yyz
Motivator

Put "$combined_token$" in the title or description of the first panel.  You can then see what is populating the token you depend upon.  Also I'm curious about your current eval, I would have opted to make the spaces literal characters or only put in a single concatenation character between tokens.

 

<eval "combined">$token1$. .$token2$. .$token3$. .$token4$. $token5$</eval>
I would try
<eval "combined">$token1$." ".$token2$." ".$token3$." ".$token4$." ".$token5$</eval>
or
<eval "combined">$token1$.$token2$.$token3$.$token4$.$token5$</eval>

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

All tokens in a search must have a non-null value before the search will run.

Try setting the null tokens to empty strings ("") before the search.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...