Dashboards & Visualizations

Populate Dropdown with file/foldernames in specific directorypath

vishal2211
New Member

I have to create a dashboard where I will have a dropdown which gets populated with filename/foldername from specific network path. How can I achieve this.

e.g. I am having network path "\VM\ResultsDir". I want to display all files/folder names inside this directory in drodpwn. How can I achieve this in splunk dashboard?

Tags (1)
0 Karma
1 Solution

FrankVl
Ultra Champion

Do you have those values in Splunk somehow already? I assume you do, since you want to create a dropdown to filter for them?

So assuming you for instance have some index=foo with events that have a file field. You can populate the dropdown with a search like:

index=foo file="\\VM\ResultsDir\*" | stats count by file | fields file

If you don't have the data like that, or you need a full list rather than relying on the values seen in events, I guess you could create some scripted input on the respective host that produces a directory list, ingest that into splunk and maybe even load it into a lookup.

View solution in original post

0 Karma

FrankVl
Ultra Champion

Do you have those values in Splunk somehow already? I assume you do, since you want to create a dropdown to filter for them?

So assuming you for instance have some index=foo with events that have a file field. You can populate the dropdown with a search like:

index=foo file="\\VM\ResultsDir\*" | stats count by file | fields file

If you don't have the data like that, or you need a full list rather than relying on the values seen in events, I guess you could create some scripted input on the respective host that produces a directory list, ingest that into splunk and maybe even load it into a lookup.

0 Karma

vishal2211
New Member

Can you please also guide me how to add index for such scenario? I am fairly new to splunk. I tried to create index via Splunk web > Add Data > monitor> File Or Directory > UNC Path. When I tried to search with given index it shows no result.

0 Karma

FrankVl
Ultra Champion

That sounds like a new question, which is best asked separately to prevent confusion. And to answer it it would help a lot if you provide some more details than just the GUI page used and "it shows no result". This page in the docs also gives some good hints on troubleshooting missing data: https://docs.splunk.com/Documentation/Splunk/7.3.0/Troubleshooting/Cantfinddata

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...