Hi guys!
I have a dashboard with a text input that are connected with a token ($tk1$) , and a "Submit" button.
What I want is, when click on Submit, to read the typed text on the input, and run a | table... | collect...
Here is my dashboard code:
<form version="1.1">
<label>LAB2</label>
<fieldset submitButton="true" autoRun="false">
<input type="text" token="tk3">
<label>Comments</label>
</input>
</fieldset>
<row>
<panel>
<table>
<search>
<query>index=lab sourcetype=lab2 A=$TK1$ B=$TK2$
| eval C="$tk3$"
| table A B C</query>
</search>
</table>
</panel>
</row>
</form>
Surround the tokens with quotes (").... and allow run query as part of SPL safeguards.
https://docs.splunk.com/Documentation/Splunk/9.0.4/Security/SPLsafeguards#SPL_safeguards_for_risky_c...
<form version="1.1">
<label>LAB2</label>
<fieldset submitButton="true" autoRun="false">
<input type="text" token="tk1">
<label>Token1</label>
</input>
<input type="text" token="tk2">
<label>Token2</label>
</input>
<input type="text" token="tk3">
<label>Comments</label>
</input>
</fieldset>
<row>
<panel>
<table>
<search>
<query>|makeresults
|eval A="$tk1$"
|eval B="$tk2$"
| eval C="$tk3$"
| table A B C
|collect index=summary</query>
</search>
</table>
</panel>
</row>
</form>