Dashboards & Visualizations

How to dynamically Set token from search on ITSI glass table?

gpugliese
Explorer

Hi Community,

I am trying to set a token based on a search in an ITSI glass table, but I cannot find any way to do it "dynamically", even by changing the JSON code of the glass table.

My final goal is using the token value to set the color of an icon based on the value returned by the related search. According to what I found, the only option to colorize an icon with a value changing dynamically is by using a token (and this works, with a static token set via text input with an hex value corresponding to a color, e.g. "#FFFFFF"). The only reference documentation I can find is https://docs.splunk.com/Documentation/ITSI/4.8.0/SI/Inputs#How_inputs_connect_to_visualizations

Below, the code of the icon, with its color set to a token named "vizcolor":

{
    "type""viz.singlevalueicon",
    "options": {
        "showValue"false,
        "icon""splunk-enterprise-kvstore://6001e599aea29f5df6382024",
        "color""$vizcolor$"
    },
    "dataSources": {
        "primary""ds_XXXXXX"
    }
}
 

In conclusion, I would like to know if any one of you can suggest me how to set a token from a search result on a glass table (examples are appreciated).

Thanks,

G.P.

Labels (3)

shandr
Path Finder

Depending on your version, 
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2203/DashStudio/searchTokens#Example_of_settin...

       "ds_m45g5mF6": {
           "type": "ds.search",
           "options": {
               "query": "index=_internal \n| stats count by sourcetype",
               "enableSmartSources": true
           },
           "name": "Activity by Sourcetype"


 

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...

Expert Tips from Splunk Education, Observability in Action, Plus More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...