Dashboards & Visualizations

How to import different CSV regarding a field token ?

apomona
Explorer

Hello,

I've set up a field choice called "ASSETtoken" where the user can select "value1", "value2" or "all".

I would like in a Single Value element do something like count all lines in the column "columnX" in CSVValue1 or CSVValue2 or both depending on the selection.

Any tip is welcome (started Splunk 2/3 days ago)

Thx all !

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @apomona,

please, try something like tis:

<your_search
| eval columnX=coalesce(CSVValue1,CSVValue2)
| search columnX="$ASSETtoken$"
| sort columnX
| table columnX

Ciao.

Giuseppe

apomona
Explorer

Hey, 

I just tried but I don't think this is working properly.

ASSETtoken can be either Value1, Value2 or All. It is set by the user. If it is Value1, I want to use File1.csv, Value2=> File2.csv, All => File1 + File2. In both files there is a column called columnX

Here is my code following your example: 

| inputlookup File1.csv | inputlookup File2.csv
| eval columnX=coalesce(File1.csv,File2.csv)
| search columnX="$ASSETtoken$"                                
| sort columnX
| table columnX

 

 

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...