Dashboards & Visualizations

How to get the job.resultCount for a dashboard panel search, not the base search?

roukepouw
Explorer

When using the following Dashboard and check the job.resultCount for the table element, it returns the number of the base search $QUERY$, not that of the filtered search $QUERY$ | where $FILTER$=1. How do I obtain that number of results?

<dashboard>
<search id="baseSearch">
     <query>$QUERY$</query>
</search>
<row>
  <table>

      <search base="baseSearch">
        <query>| where $FILTER$=1</query>
        <progress]
            <condition match="'job.resultCount' ] 1">
                <set token="check">true</set>
            </condition>
            <condition>
                <set token="check">false</set>
            </condition>
        </progress>
    &lt;/search&gt;
  </table>
   </panel>
</row>
</dashboard>
0 Karma

somesoni2
Revered Legend

Try like this

<dashboard stylesheet="eval_tokens.css">
  <label>Eval Tokens</label>
  <row>
    <panel >
      <chart>
        <title>Top sourcetypes for index=_internal</title>
        <search>
          <query>index=_internal sdfdsfdfdfdf|  top sourcetype</query>
          <earliest>-2h</earliest>
          <latest>now</latest>
          <progress>
            <eval token="duration">tonumber('job.resultCount')</eval>
          </progress>
        </search>

      <h3>Duration</h3>
      <div class="custom-result-value">$duration$</div>
  </html>

        <option name="charting.chart">bar</option>
      </chart>
     </panel>
  </row>
</dashboard>
Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...