Dashboards & Visualizations

How to pass a token in to Dashboard with OR?

kiran331
Builder

Hello,

I have a field status with values new, active, reopen. I have to pass status values as (New or active or reopen).when I pass token with values its taking as AND, but a event has only one of them. How can I do it?

Tags (2)
0 Karma
1 Solution

rjthibod
Champion

Do you mean you are passing these values into a search,e.g. index=foo $status_token$ | ... ?

If so, you can use gentimes and format to reformat the value.

Suppose your field is called "status" and you want to search (status=new OR status=active OR status=reopen). So, assuming I understand your plan is to set the token value to "new active reopen", you can use the following to search using OR instead of AND logic.

index=foo [| gentimes start=-1 | eval status = "$status_token$" | table status | makemv status | mvexpand status | format]

This should get converted to the following when applied

index=foo ( ( status="open" ) OR ( status="new" ) OR ( status="reopen" ) )

View solution in original post

0 Karma

rjthibod
Champion

@kiran331, did my answer help you? If so, please accept it. If not, please clarify.

0 Karma

kiran331
Builder

It worked Thanks!

0 Karma

rjthibod
Champion

Do you mean you are passing these values into a search,e.g. index=foo $status_token$ | ... ?

If so, you can use gentimes and format to reformat the value.

Suppose your field is called "status" and you want to search (status=new OR status=active OR status=reopen). So, assuming I understand your plan is to set the token value to "new active reopen", you can use the following to search using OR instead of AND logic.

index=foo [| gentimes start=-1 | eval status = "$status_token$" | table status | makemv status | mvexpand status | format]

This should get converted to the following when applied

index=foo ( ( status="open" ) OR ( status="new" ) OR ( status="reopen" ) )

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...