Dashboards & Visualizations

How to set token in search and use it in a chart title?

seva98
Path Finder

In my dashboard I have two ChartElements (el1 with search1 and el2 with search2).

I need to set token $hierarchy$ in search1 and use it in title of el2.

I was able to use token in the title and set it manually with setToken("hierarchy", "need to have $hiearchy$ here") but I am not sure how to set token inside the search1.

For example, I need functionality similar to this (this example is not working) ... | eval $hierarchy$="new title"which will make title of el2 equal to new title

Btw, I am using dashboard that was converted into HTML.

0 Karma
1 Solution

seva98
Path Finder

Finally found a solution.
HTML part:

<div class="panel-head">
   <h3>$hierarchy$</h3>
</div>

JS part:

// right under var search1 = new PostProcessManager({ ... })

new SearchEventHandler({
            managerid: 'search1',
            event: 'done',
            actions: [
                {
                    'type': 'set',
                    'token': 'hierarchytop',
                    'value': '$result.hierarchy$'
                }
            ]
        }

View solution in original post

0 Karma

seva98
Path Finder

Finally found a solution.
HTML part:

<div class="panel-head">
   <h3>$hierarchy$</h3>
</div>

JS part:

// right under var search1 = new PostProcessManager({ ... })

new SearchEventHandler({
            managerid: 'search1',
            event: 'done',
            actions: [
                {
                    'type': 'set',
                    'token': 'hierarchytop',
                    'value': '$result.hierarchy$'
                }
            ]
        }
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...