Dashboards & Visualizations

How to pass values between 2 input lookups?

phwork
Explorer

Hello

I have 2 lookups.

The first one will be getting inputs from a dashboard and getting saved to the lookup(for example: a column called <username>).

The second lookup has the same data from the first lookup with additional information(for example : columns called <username>,<usercity>,<userstate> ,<usercountry>).

I'm trying to take the inputs from the first lookup > use information from the second lookup> and map it out using a clustermap. 

Can someone help me with the spl ?

 

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @phwork,

let me understand: you have two lookups, both have the same first column and the second has more columns.

You want to use the first as input dropdown for the second to display in dashboard, is it correct?

If this is your need, only one question: why you want to use two lookups instead only one (obviously the complete one)?

you could try something like this :

<form>
  <label>test</label>
  <fieldset submitButton="false">
    <input type="dropdown" token="username" searchWhenChanged="true">
      <label>username</label>
      <choice value="*">All</choice>
      <search>
        <query>| inputlookup your_lookup.csv | fields username</query>
        <earliest>$Time.earliest$</earliest>
        <latest>$Time.latest$</latest>
      </search>
      <fieldForLabel>username</fieldForLabel>
      <fieldForValue>username</fieldForValue>
      <default>*</default>
      <prefix>username="</prefix>
      <suffix>"</suffix>
    </input>
  </fieldset>
  <row>
    <panel>
      <table>
        <search>
          <query>
             | inputlookup your_lookup.csv WHERE $username$
             | table username usercity userstate
          </query>
          <earliest>$Time.earliest$</earliest>
          <latest>$Time.latest$</latest>
          <sampleRatio>1</sampleRatio>
        </search>
        <option name="drilldown">none</option>
      </table>
    </panel>
  </row>
</form>

Ciao.

Giuseppe

0 Karma

phwork
Explorer

Hello

Thank you for your reply.

The reason for having 2 lookups is that the  first one contains only 50 and a few more as the users enter them in. The second lookup contains a list of 500 records.

Only the entries from the first lookup matter, and need to be displayed on the map using the information in the second table.

And both are on different dashboards, the users enter their information on one dashboard and the results are processed and displayed on another dashboard. It cant be on the same dash.

Thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...