Hi all, new to Splunk.
I have a Dashboard Input with a token which is assigned a value which can be a string with spaces. For example it might be a subject of an email like "RE: How was work".
Now I have a search in the same dashboard which uses that token like message_subject=$search_subject$
but it returns nothing. I suspect it is due to the spaces in the value and i need to add quotes to the token.
Is there an easy way to do this?
Thanks!
Hi Zerophage,
if spaces are the problem, try using brackets:
message_subject="$search_subject$"
Bye.
Giuseppe
Thanks! Why did I not think of that, was trying all sorts other than the most obvious haha.
Hi Zerophage,
if spaces are the problem, try using brackets:
message_subject="$search_subject$"
Bye.
Giuseppe