Dashboards & Visualizations

In a Simple XML dashboard, is it possible to set a token when a user clicks the submit button?

drewski3420
New Member

In a Simple XML dashboard, is it possible to set a token when a user clicks the submit button?

I'm setting a token in the init block. Then, I'd like to change it, potentially, based on the values of multiple inputs. After they've all been filled out (or not), and the user has pressed Submit to run the search.

As an example:

<form>
  <init>
    <set token="query">| makeresults | eval x= "Yes" | table x</set>
  </init>
  <fieldset submitButton="true" autoRun="false">
    <input type="dropdown" token="Input1">
      <label>Input1</label>
      <choice value="A">A</choice>
      <choice value="B">B</choice>
    </input>
    <input type="dropdown" token="Input2">
      <label>Input2</label>
      <choice value="C">C</choice>
      <choice value="D">D</choice>
    </input>
  </fieldset>

  <-- Here's where I'd like to set the new $query$, after submit
    if $Input1$ == "A" and $Input2$ == "C" then $query$ = "| makeresults | eval x= "No" | table x"
  -->
  <row>
    <panel>
      <table>
        <search>
          <query>$query$</query>

Obviously this is not the search I'm trying to modify, just an example.

0 Karma
1 Solution

dmarling
Builder

This can be accomplished by having a search in the background process your inputs to generate the query token based on the results of that search. Here's a run anywhere example using the exact same concept you originally posted:

<dashboard>
  <init>
    <set token="query">| makeresults count=1 | eval x= "Yes" | table x</set>
  </init>
  <label>demodash</label>
  <fieldset submitButton="true" autoRun="false">
    <input type="dropdown" token="Input1">
      <label>Input1</label>
      <choice value="A">A</choice>
      <choice value="B">B</choice>
    </input>
    <input type="dropdown" token="Input2">
      <label>Input2</label>
      <choice value="C">C</choice>
      <choice value="D">D</choice>
    </input>
  </fieldset>
  <search>
    <query>| makeresults count=1 
| eval search=if("A"=$Input1|s$ AND "C"=$Input2|s$,  "| makeresults | eval x=\"No\" | table x", "| makeresults | eval x=\"Yes\" | table x")
| table search</query>
    <done>
      <condition match="$job.doneProgress$=1">
        <set token="query">$result.search$</set>
      </condition>
    </done>
  </search>
  <row>
    <panel>
      <table>
        <search>
          <query>$query$</query>
        </search>
      </table>
    </panel>
  </row>
</dashboard>

I added a second part to the if statement so it would fall back to the query you had in your init section if Input1 does not equal A and Input2 does not equal C. Let me know if you have any questions.

If this comment/answer was helpful, please up vote it. Thank you.

View solution in original post

dmarling
Builder

This can be accomplished by having a search in the background process your inputs to generate the query token based on the results of that search. Here's a run anywhere example using the exact same concept you originally posted:

<dashboard>
  <init>
    <set token="query">| makeresults count=1 | eval x= "Yes" | table x</set>
  </init>
  <label>demodash</label>
  <fieldset submitButton="true" autoRun="false">
    <input type="dropdown" token="Input1">
      <label>Input1</label>
      <choice value="A">A</choice>
      <choice value="B">B</choice>
    </input>
    <input type="dropdown" token="Input2">
      <label>Input2</label>
      <choice value="C">C</choice>
      <choice value="D">D</choice>
    </input>
  </fieldset>
  <search>
    <query>| makeresults count=1 
| eval search=if("A"=$Input1|s$ AND "C"=$Input2|s$,  "| makeresults | eval x=\"No\" | table x", "| makeresults | eval x=\"Yes\" | table x")
| table search</query>
    <done>
      <condition match="$job.doneProgress$=1">
        <set token="query">$result.search$</set>
      </condition>
    </done>
  </search>
  <row>
    <panel>
      <table>
        <search>
          <query>$query$</query>
        </search>
      </table>
    </panel>
  </row>
</dashboard>

I added a second part to the if statement so it would fall back to the query you had in your init section if Input1 does not equal A and Input2 does not equal C. Let me know if you have any questions.

If this comment/answer was helpful, please up vote it. Thank you.
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...