Dashboards & Visualizations

How to set token in a filter to show panel in dashboard

avi7326
Path Finder

I have a filter of Entity which has token t_entity and in drilldown it has All, C2V ,C2C and Cases . And I have different panels of this which is showing counts. I have a separate panel of C2V counts which I only want to show when it is selected from the filter .
Filter name-Entity
Token Name- t_entity
How is this possible to show a panel when we select it from the filter.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Use the depends option on the panel to control whether is is shown or not.

<panel depends="$t_entity$">
...
</panel>

The panel will be shown if the specified token has any value, which is not exactly what you're looking for.  In this case, we want to set a different token if t_entity has a specific value.

<input token=t_entity ...>
  ...
  <change>
    <condition value="C2V">
      <set token="show_panel">1</set>
    </condition>
    <condition>
      <unset token="show_panel" />
    </condition>
  </change>
</input>
...
<panel depends="$show_panel$">
...
</panel>

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

avi7326
Path Finder

where should I put this in my query as my query starts with-

<row>
<panel>
<title></title>
<single><search>

<query></query>
<earliest>

<latest>
<sampleRatio>1</sampleratio>
</search>
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's not a plug-n-play answer.  Use it as a guide for building your dashboard.  The <input> section shows parts that should be in your <input> section and the <panel> section shows how to make the panel show or hide based on a token.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...