Dashboards & Visualizations

How to populate the values of a drop-down based on the value selected in another drop-down?

xvxt006
Contributor

Hi,

I have 2 drop-downs in a form on a dashboard. Based on what i select in the first drop-down, I want it to dictate the values in the 2nd drop-down. How can this be done? any examples, suggestions available?

Tags (1)
0 Karma

splunker12er
Motivator

Did you checked out sideview utils app ?

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Yes, see Form examples in the documentation for a written description, and download the Splunk 6.x Dashboard Examples app for an implemented example.

xvxt006
Contributor

Thank you. I will try this and let you know.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Same basic strategy, just with a small detour.

Define your first dropdown static as you normally would.
Define your second dropdown dynamic with a search like this:

| stats count | eval values = "one two three four five" | makemv values | mvexpand values

That gives you a static list of five values. You can now append filters based on your first value like this:

... | where "$firstvalue$"="foo" OR values="one" OR values="two" OR values="three"

That would keep all values if the first selected value is "foo", and keep only the first three values if it's not.

xvxt006
Contributor

Form examples show how to populate data dynamically. But in my case, dropdown values are static only. for example when i select first value from first dropdown, all values from 2nd dropdown are applicable. But when i select 2nd value from first drop down, only subset of values from 2nd dropdown are applicable. Do you know how to achieve this?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...