Dashboards & Visualizations

How to populate a dropdown using a search SPL query in Dashboard Studio?

mihir_hardas
Explorer

I need to create a simple dropdown and populate it using search query in Dashboard Studio. 

We can do this in Dashboard classic but how to do it in Dashboard Studio.

Then once the user selects any option, how to pass the option to another search query. Like a token

Labels (2)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@mihir_hardas - You can set dataSource to your inputs. And add a search as dataSource.

"inputs": {
       "input_RtgCL23i": {
           "options": {
               "items": ">frame(label, value) | prepend(formattedStatics) | objects()",
               "token": "user"
           },
           "title": "Select user",
           "type": "input.dropdown",
           "dataSources": {
               "primary": "ds_eiFyjWZU"
           },
           "context": {
               "formattedConfig": {
                   "number": {
                       "prefix": ""
                   }
               },
               "formattedStatics": ">statics | formatByType(formattedConfig)",
               "statics": [
                   [
                       "All"
                   ],
                   [
                       "*"
                   ]
               ],
               "label": ">primary | seriesByName(\"user\") | renameSeries(\"label\") | formatByType(formattedConfig)",
               "value": ">primary | seriesByName(\"user\") | renameSeries(\"value\") | formatByType(formattedConfig)"
           }
       },

Examples picked from this page - https://docs.splunk.com/Documentation/Splunk/8.2.6/DashStudio/inputs#Example:_Search-based_cascading... 

there are other examples also there.

 

I hope this helps!!

0 Karma

mihir_hardas
Explorer

Okay thanks and where to write the actual splunk query ? 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Splunk Certification Support Alert | Pearson VUE Outage

Splunk Certification holders and candidates!  Please be advised of an upcoming system maintenance period for ...

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...