Dashboards & Visualizations

Lookup question for dashboard

deepusoundar
Engager

Hi,
I used the below to lookup for a query from a lookup file/table and execute it.

Lookup file - search_queries.csv with Name and Search has two columns.
[where search has the query that has to be selected upon selecting the corresponding Name]

 <form>
 1.   <label>Run Search from Lookup</label>
 2.   <fieldset submitButton="false">
 3.     <input type="time" token="tokTime" searchWhenChanged="true">
 4.       <label>Select Time</label>
 5.       <default>
 6.         <earliest>-24h@h</earliest>
 7.         <latest>now</latest>
 8.       </default>
 9.     </input>
 10.   </fieldset>
 11.   <row>
 12.     <panel>
 13.       <title>Search Based on Lookup</title>
 14.       <input type="dropdown" token="tokSearchQuery" searchWhenChanged="true">
 15.         <label>Select Search Query (from lookup)</label>
 16.         <fieldForLabel>Name</fieldForLabel>
 17.         <fieldForValue>Search</fieldForValue>
 18.         <search>
 19.           <query>| inputlookup search_queries.csv | table Name Search</query>
 20.         </search>
 21.       </input>
 22.       <chart>
 23.         <search>
 24.           <query>$tokSearchQuery$</query>
 25.           <earliest>$tokTime.earliest$</earliest>
 26.           <latest>$tokTime.latest$</latest>
 27.         </search>
 28.         <option name="charting.chart.showDataLabels">minmax</option>
 29.         <option name="charting.chart.stackMode">stacked</option>
 30.         <option name="refresh.display">progressbar</option>
 31.       </chart>
 32.     </panel>
 33.   </row>
 34. </form>
Tags (1)
0 Karma

lakshman239
Influencer

Try changing line 24 to `search $tokSearchQuery$

0 Karma

tiagofbmm
Influencer

where is the question?

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...