Dashboards & Visualizations

How to use multiple tokens with multiple searches in a form?



I am redesigning a dashboard where I'd like the text inputs token to preload in order to use downstream within another token.

Here is a simpler version of the Simple XML:

    <fieldset submitButton="true">
        <input type="text" token="name1">
        <input type="text" token="name2">
        <input type="text" token="name3">
        <input type="text" token="name4">

        <input type="dropdown" token="search_results" searchWhenChanged="false">
            <choice value="*">All</choice>
            <choice value="`search1A` $name1$ $name2$ $name3$ $name4$ | `search1B`">Type</choice>
            <choice value="`search2A` $name1$ $name2$ $name3$ $name4$ | `search2B`">Type</choice>
            <choice value="`search3A` $name1$ $name2$ $name3$ $name4$ | `search3B`">Type</choice>
            <choice value="`search4A` $name1$ $name2$ $name3$ $name4$ | `search4B`">Type</choice>

            <table id="search_results">
                <title>Your Search Results:</title>
                    <![CDATA[ $search_results$ ]]>

There may be a more optimal way of creating this functionality. Any insight would be greatly appreciated.


0 Karma

Splunk Employee
Splunk Employee

Text input tokens can be passed via the query string as part of the URL that launches the page.

In the URL string the first parameter starts with ? then the others use &: https://someurl:8000?form.name1=abc&form.name2=xyz

This will set those values when the page loads for the user.

0 Karma


Thanks for your answer, sjohnson. Instead of doing any sort of drilldown here, I was hoping that if we could add some value in to the text input and click submit, that value would get passed downstream to the query that runs all in the same view. I may end up re-engineering this one :-).

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!