Dashboards & Visualizations

How to get dashboard token value from input to another input?

igne
Observer

I've got a dashboard where i want to append multiple searches together based on checkbox inputs, but the variables aren't resolving?  I can get conditional tokens to set the entire firewall_search string,  but I don't want to have to setup all the available options if i can just get the variables to use their value instead of the variable.
Summary - I am asking for $src_ip$ and then trying to use that in a checkbox token value, nested in another variable, but it doesn't resolve the nested variable, and instead i just get the $src_ip$ name
example xml
<input type="text" token="src_ip">
  <label>Source IP</label>
</input>
<input type="checkbox" token="firewall_search">
  <label>Firewalls</label>
  <choice value="append [search index=index1 src_ip=$src_ip$  other_specific_search_Stuff_to_index1 ]">firewall 1</choice>
<choice value="append [search index=index2 src_ip=$src_ip$  searches_different_from_1 ]">firewall 2</choice>
<delimiter> | </delimiter>
</input>
</fieldset>
<row>
<panel>
<title>dependent search</title>
<table>
<search>
<query>$firewall_search$ | stats count by index, src_ip, otherfields</query>
<earliest>$time_pick.earliest$</earliest>
<latest>$time_pick.latest$</latest>
</search>

When i run that, $firewall_search$ resolves to the choice value listed, but doesn't resolve $src_ip$ to the value set in the form

Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try it like this

    <input type="checkbox" token="firewall_search">
      <label>Firewalls</label>
      <choice value="search index=index1 other_specific_search_Stuff_to_index1">firewall 1</choice>
      <choice value="search index=index2 searches_different_from_1">firewall 2</choice>
      <valuePrefix>| append [ </valuePrefix>
      <delimiter> </delimiter>
      <valueSuffix> src_ip=$src_ip$ ]</valueSuffix>
    </input>
0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...