Dashboards & Visualizations

How to improve the filter input?

maayan
Path Finder

Hi,

I implemented an input filter, but i want to improve it.
Customers want to select multiple values from the filter and then select more values. in the current situation they need to select 'All ' and then select the values again (each time they want to add values they need to select All-->select values-->remove All)
in addition, they want to select all values except one value, which currently takes time to do.

Is there a smarter filter input in Splunk?


my code:

<input type="multiselect" token="WinTimeStamp" searchWhenChanged="true">
<label>Time</label>
<choice value="%">All</choice>
<default>%</default>
<prefix>(</prefix>
<suffix>)</suffix>
<valuePrefix>(WinTimeStamp like("</valuePrefix>
<valueSuffix>"))</valueSuffix>
<delimiter> OR </delimiter>
<fieldForLabel>WinTimeStamp</fieldForLabel>
<fieldForValue>WinTimeStamp</fieldForValue>
<search>
<query> | where $Name$ 
| dedup WinTimeStamp
| sort WinTimeStamp</query>
</search>
</input>



Thanks,

Maayan

Labels (1)
0 Karma
1 Solution

bharathkumarnec
Contributor

@maayan I would assume if you open the dashboard and there are three dots to the top right corner, if you click there you will see an option to clone in dashboard studio..

View solution in original post

bharathkumarnec
Contributor

@maayan Please check multiselect input using Splunk Dashboard Studio
https://docs.splunk.com/Documentation/Splunk/latest/DashStudio/inputMulti

0 Karma

maayan
Path Finder

how to change my code to something like the filter in the image? 

maayan_0-1699956245686.png

https://docs.splunk.com/Documentation/Splunk/9.1.1/DashStudio/inputMulti

0 Karma

bharathkumarnec
Contributor

@maayan clone the classic dashboard to dashboard studio?

0 Karma

maayan
Path Finder

how can i convert classic dashboard type to studio? 

0 Karma

bharathkumarnec
Contributor

@maayan I would assume if you open the dashboard and there are three dots to the top right corner, if you click there you will see an option to clone in dashboard studio..

maayan
Path Finder

nice idea

the conversation doesn't really works but it's a nice direction!

Anyway, the filter doesn't work. the error (studio) :"Cannot convert undefined or null to object"

code:

{
    "options": {
        "items": [
            {
                "label""All",
                "value""*"
            }
        ],
        "defaultValue""*",
        "token""WinTimeStamp"
    },
    "title""Multiselect Input Title",
    "type""input.multiselect",
    "dataSources": {
        "primary""ds_ICA_General"
    }
}


classic studio code:
<input type="multiselect" token="WinTimeStamp" searchWhenChanged="true">
<label>Time</label>
<choice value="%">All</choice>
<default>%</default>
<prefix>(</prefix>
<suffix>)</suffix>
<valuePrefix>(WinTimeStamp like("</valuePrefix>
<valueSuffix>"))</valueSuffix>
<delimiter> OR </delimiter>
<fieldForLabel>WinTimeStamp</fieldForLabel>
<fieldForValue>WinTimeStamp</fieldForValue>
<search base="ICA_General">
<query> 
| stats values(WinTimeStamp) as WinTimeStamp_
| sort WinTimeStamp_</query>
</search>
</input>
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...