Dashboards & Visualizations

Populating Form Dropdowns via searches

mcwomble
Path Finder

I have a question regarding the population of dropdowns via saved searches.

The examples in the Splunk documentation show a search similar to the following:

   <populatingSearch fieldForValue="suser" fieldForLabel="suser"><!CDATA[sourcetype=p4change | rex "user=(?<suser>\w+)@" | stats count by suser]]></populatingSearch>

However, I am slightly confused (maybe because the search in the examples is quite complex) on how this is carried out in practice.

I wish to populate the dropdown with the contents of the partner field which has up to 200 different values within the indexed data. The string being as follows:

2010/12/13@13:31:22,billstats,partner=XXXX,cde=XX,usd=XX

How would I write the example population string in a way which can parse my indexed data in a way that could populate the dropdown?

Tags (1)
0 Karma
1 Solution

ziegfried
Influencer
<populatingSearch fieldForValue="partner" fieldForLabel="partner">
    sourcetype=your_sourcetype | fields partner | dedup partner
</populatingSearch>

View solution in original post

ziegfried
Influencer
<populatingSearch fieldForValue="partner" fieldForLabel="partner">
    sourcetype=your_sourcetype | fields partner | dedup partner
</populatingSearch>

mcwomble
Path Finder

Brilliant! That works a treat

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...