Dashboards & Visualizations

How to unset a token in a a Splunk 6.2 Simple XML dashboard?


I am not sure why I cannot find a real answer in all the questions asked on this subject. They all seem like hacks and workarounds.

All I want to do is re-populate the token behind an input when the values change. What is happening instead is that it just keeps appending the token based on all the previous inputs.

This is Splunk 6.2 and here is the input

<input type="checkbox" token="operation" searchWhenChanged="false">
        <query>search query</query>
      <delimiter> OR </delimiter>
      <choice value="*">All</choice>
0 Karma


Hello, this is an example you can use:

    <input type="dropdown" token="operation" searchWhenChanged="true">
            <label>Change the ticket status Update:</label>
            <choice value="Open">Open</choice>
            <choice value="Closed">Closed</choice>
              <condition value="Open">
                <unset token="operation"></set>
                <set token="new_operation">mynewoperation</set>
              <condition value="Closed">
             <unset token="operation"> </set>
                <set token="new_operation2"> mynewoperation2</set>

Splunk Employee
Splunk Employee

Minor change to the above, you need to close the tag. So:

<unset token="operation" />
<unset token="operation"></unset>

Also note that if you are looking to unset a token (that is being set as part of the base input), you need to do the following:

<unset token="operation"/>
<unset token="form.operation"/>


I am not quite sure how this is to work. I am calling the token $operation$ in a dashboard panel driven by this input. It appears I am resetting a new token value to something other than $operation$ in your example which will not be recognized in my search.

0 Karma


Thanks nfilippi. Was an error.