Hi,
I implemented an input filter, but i want to improve it.
Customers want to select multiple values from the filter and then select more values. in the current situation they need to select 'All ' and then select the values again (each time they want to add values they need to select All-->select values-->remove All)
in addition, they want to select all values except one value, which currently takes time to do.
Is there a smarter filter input in Splunk?
my code:
<input type="multiselect" token="WinTimeStamp" searchWhenChanged="true">
<label>Time</label>
<choice value="%">All</choice>
<default>%</default>
<prefix>(</prefix>
<suffix>)</suffix>
<valuePrefix>(WinTimeStamp like("</valuePrefix>
<valueSuffix>"))</valueSuffix>
<delimiter> OR </delimiter>
<fieldForLabel>WinTimeStamp</fieldForLabel>
<fieldForValue>WinTimeStamp</fieldForValue>
<search>
<query> | where $Name$
| dedup WinTimeStamp
| sort WinTimeStamp</query>
</search>
</input>
Thanks,
Maayan
@maayan I would assume if you open the dashboard and there are three dots to the top right corner, if you click there you will see an option to clone in dashboard studio..
@maayan Please check multiselect input using Splunk Dashboard Studio
https://docs.splunk.com/Documentation/Splunk/latest/DashStudio/inputMulti
how to change my code to something like the filter in the image?
https://docs.splunk.com/Documentation/Splunk/9.1.1/DashStudio/inputMulti
@maayan clone the classic dashboard to dashboard studio?
how can i convert classic dashboard type to studio?
@maayan I would assume if you open the dashboard and there are three dots to the top right corner, if you click there you will see an option to clone in dashboard studio..
nice idea
the conversation doesn't really works but it's a nice direction!
Anyway, the filter doesn't work. the error (studio) :"Cannot convert undefined or null to object"
code: