Dashboards & Visualizations

How to group values with similar pattern into the choices in a dropdown?

Julia1231
Communicator

Hi, 

I'm searching a way to create a dropdown in Dashboard, in which the values in the dropdown is grouped.

For example with the table below, I want to have a dropdown with 2 values called "Site": Washington, California. Then later in the statistic table, it will list IDs according to the "Site"

Address ID
1 Microsoft Way, Redmond, Washington 132
15 Microsoft Way, Redmond, Washington 456
10 Microsoft Way, Redmond, Washington 789
1 Infinite Loop, Cupertino, California 111
2 Infinite Loop, Cupertino, California 222
3 Infinite Loop, Cupertino, California 489

I imagine to have a list of label in the dropdown, then search for the values correspond with each lable:

 

 

    <input type="dropdown" token="site" searchWhenChanged="true">
      <label>Site</label>
      <choice value="Washington">Washington</choice>
      <choice value="California">California</choice>
      <choice value="*">All</choice>
    </input>

 

 

 

 

 

|inputlookup address.csv
|where like(Address,"%Washington%")

 

 

But  I don't know how to put it together to work.

Do you have an idea how it can work or another idea, please?

Thanks in advanced!

Labels (3)
Tags (2)
0 Karma
1 Solution

Julia1231
Communicator

@ITWhisperer Thanks for your reply,  I don't know why but it shows 0 result for me.

However I find this works:

|inputlookup address.csv 
|eval site=case(like(address,"%Washington%"), "Washington", like(address,"%California%"), "California",1=1,"No")

 

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

|inputlookup address.csv
|where match(Address,$site$)

 

0 Karma

Julia1231
Communicator

@ITWhisperer Thanks for your reply,  I don't know why but it shows 0 result for me.

However I find this works:

|inputlookup address.csv 
|eval site=case(like(address,"%Washington%"), "Washington", like(address,"%California%"), "California",1=1,"No")

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...