Dashboards & Visualizations

How to populate a dropdown using a search SPL query in Dashboard Studio?

mihir_hardas
Explorer

I need to create a simple dropdown and populate it using search query in Dashboard Studio. 

We can do this in Dashboard classic but how to do it in Dashboard Studio.

Then once the user selects any option, how to pass the option to another search query. Like a token

Labels (2)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@mihir_hardas - You can set dataSource to your inputs. And add a search as dataSource.

"inputs": {
       "input_RtgCL23i": {
           "options": {
               "items": ">frame(label, value) | prepend(formattedStatics) | objects()",
               "token": "user"
           },
           "title": "Select user",
           "type": "input.dropdown",
           "dataSources": {
               "primary": "ds_eiFyjWZU"
           },
           "context": {
               "formattedConfig": {
                   "number": {
                       "prefix": ""
                   }
               },
               "formattedStatics": ">statics | formatByType(formattedConfig)",
               "statics": [
                   [
                       "All"
                   ],
                   [
                       "*"
                   ]
               ],
               "label": ">primary | seriesByName(\"user\") | renameSeries(\"label\") | formatByType(formattedConfig)",
               "value": ">primary | seriesByName(\"user\") | renameSeries(\"value\") | formatByType(formattedConfig)"
           }
       },

Examples picked from this page - https://docs.splunk.com/Documentation/Splunk/8.2.6/DashStudio/inputs#Example:_Search-based_cascading... 

there are other examples also there.

 

I hope this helps!!

0 Karma

mihir_hardas
Explorer

Okay thanks and where to write the actual splunk query ? 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...