Dashboards & Visualizations

How to modify a token

syk19567
Explorer

Hi community,

I have a dropdown for environments like DEV/CT/PROD, and saved it into a token `SDLC`.
Now I would like to define another token `new_sdlc`. It's "ctpm" when `SDLC` is "pm"; Otherwise, it's the same value as `SDLC`.

In the end, I found a way working but a bit stupid, simply because it seems "!=" is not allowed so I have to list all conditions.

I've checked a few posts but didn't find a working and elegant way. I bet there is one. Looking forward to your help.

Here is my code:

<fieldset submitButton="false">
<input type="time" token="field1">
<label></label>
<default>
<earliest>-24h@h</earliest>
<latest>now</latest>
</default>
</input>
<input type="dropdown" token="SDLC">
<label>SDLC</label>
<choice value="prod">PROD</choice>
<choice value="ct">CT</choice>
<choice value="pm">PM</choice>
<default>prod</default>
<initialValue>prod</initialValue>
<change>
<condition label="CT">
<set token="new_sdlc">ct</set>
</condition>
<condition label="PM">
<set token="new_sdlc">ctpm</set>
</condition>
<condition label="PROD">
<set token="new_sdlc">prod</set>
</condition>
</change>
</input>
</fieldset>
Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

<change>
<eval token="new_sdlc">if("$SDLC$"=="sldc","ctpm","$SDLC$")</eval>
</change>
0 Karma

syk19567
Explorer

A problem I noticed is, the new token only gets a value when we change the origin token.

That's to say, when we opened the dashboard, although the origin token has a default value, the new token is null, thus the queries don't work. We'll see "Search is waiting for input "

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What about if you set the initial value as well as the default value?

0 Karma

syk19567
Explorer

Thank you for the response! I had a try like this (maybe not exactly the same) before posting, and it didn't work.

However, this time I pasted yours and after a slight change, it works!

Now it's like:

if(SDLC=="pm","ctpm",SDLC)

So it seems I cannot use $ and quotes. After removing them, it's good!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...