Dashboards & Visualizations

How to create a cascade dropdown?

gcescatto
New Member

Hey all,

I'm kind of new in Splunk and I would like some help on building a dashboard with a cascade dropdown. I have a script running fro different application and the idea is: once you select one of the applications (on a dropdown), it populates another dropdown with the corresponding servers (see image below).

alt text

On my Json I have a field that contains Application Name, another contains Script name and the other Server Name.
Even though I created a token ($myApp$) on my query ( | search ScriptName AppName="$myApp$"), when configuring the dropdown it didn't recognized it.

Could some one please help?
Thanks in advance.

Tags (3)
0 Karma

adonio
Ultra Champion

hello there,

please take a look at my previous answer, here:
https://answers.splunk.com/answers/527016/how-to-create-a-dependent-dropdown-and-multivalue.html
although this one using an example of csv file, the logic is the same

hope it helps

0 Karma

niketn
Legend

@gcescatto would it be possible for you to provide some sample JSON for App/Script/Server data? You can mock/anonymize any sensitive information? Also if possible can you share the code for App and Server dropdown?

If not mocked data/code can not be shared, would it be fine if we create a mock run anywhere dashboard on similar lines to assist you?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

Sukisen1981
Champion

Are you sure you have checked the search on field change option in your App token drop downs?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...