Dashboards & Visualizations

How to modify a token

syk19567
Explorer

Hi community,

I have a dropdown for environments like DEV/CT/PROD, and saved it into a token `SDLC`.
Now I would like to define another token `new_sdlc`. It's "ctpm" when `SDLC` is "pm"; Otherwise, it's the same value as `SDLC`.

In the end, I found a way working but a bit stupid, simply because it seems "!=" is not allowed so I have to list all conditions.

I've checked a few posts but didn't find a working and elegant way. I bet there is one. Looking forward to your help.

Here is my code:

<fieldset submitButton="false">
<input type="time" token="field1">
<label></label>
<default>
<earliest>-24h@h</earliest>
<latest>now</latest>
</default>
</input>
<input type="dropdown" token="SDLC">
<label>SDLC</label>
<choice value="prod">PROD</choice>
<choice value="ct">CT</choice>
<choice value="pm">PM</choice>
<default>prod</default>
<initialValue>prod</initialValue>
<change>
<condition label="CT">
<set token="new_sdlc">ct</set>
</condition>
<condition label="PM">
<set token="new_sdlc">ctpm</set>
</condition>
<condition label="PROD">
<set token="new_sdlc">prod</set>
</condition>
</change>
</input>
</fieldset>
Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

<change>
<eval token="new_sdlc">if("$SDLC$"=="sldc","ctpm","$SDLC$")</eval>
</change>
0 Karma

syk19567
Explorer

A problem I noticed is, the new token only gets a value when we change the origin token.

That's to say, when we opened the dashboard, although the origin token has a default value, the new token is null, thus the queries don't work. We'll see "Search is waiting for input "

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What about if you set the initial value as well as the default value?

0 Karma

syk19567
Explorer

Thank you for the response! I had a try like this (maybe not exactly the same) before posting, and it didn't work.

However, this time I pasted yours and after a slight change, it works!

Now it's like:

if(SDLC=="pm","ctpm",SDLC)

So it seems I cannot use $ and quotes. After removing them, it's good!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...