Dashboards & Visualizations

How to populate dropdown from lookup table?

splunkuser320
Path Finder

Hi, I need to populate the dropdown from the lookup table. I can only drop down labels from the lookup table, not the value. I need to use filter the dashboard based on the selected value. Currently, label is passing to the queries in the dashboard. 

Labels (1)
0 Karma

Manasa_401
Communicator

Hello @splunkuser320 

You have to give the lookup and table the required field you want to use as a dropdown.
In below example code, sample is the name of lookup and abc is the output field I wanted to display. So, you will get the values from abc field in the dropdown list for selection

<input type="multiselect" token="tok_name" searchWhenChanged="true">
      <label>Dropdown</label>
      <fieldForLabel>abc</fieldForLabel>
      <fieldForValue>abc</fieldForValue>
      <search>
        <query>|inputlookup sample
|table abc</query>
        <earliest>0</earliest>
        <latest></latest>
      </search>
    </input>

 

If this helps you, an upvote would be appreciated.

 

 

0 Karma

Manasa_401
Communicator

To use this dropdown selected value in dashboard query, pass the token- $tok_name$ to the SPL.

example:
|where abc="$tok_name$"

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi
If you want dropdown you should switch type="dropdown" instead of multiselect. Also I propose to use $tok_name|s$ instead of $tok_name$ to avoid issues if values have e.g. spaces. Without |s it could cause some issues with correct values. Another option for you could be to use "$tok_name$".
r. Ismo

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...