Dashboards & Visualizations

Populating Form Dropdowns via searches

mcwomble
Path Finder

I have a question regarding the population of dropdowns via saved searches.

The examples in the Splunk documentation show a search similar to the following:

   <populatingSearch fieldForValue="suser" fieldForLabel="suser"><!CDATA[sourcetype=p4change | rex "user=(?<suser>\w+)@" | stats count by suser]]></populatingSearch>

However, I am slightly confused (maybe because the search in the examples is quite complex) on how this is carried out in practice.

I wish to populate the dropdown with the contents of the partner field which has up to 200 different values within the indexed data. The string being as follows:

2010/12/13@13:31:22,billstats,partner=XXXX,cde=XX,usd=XX

How would I write the example population string in a way which can parse my indexed data in a way that could populate the dropdown?

Tags (1)
0 Karma
1 Solution

ziegfried
Influencer
<populatingSearch fieldForValue="partner" fieldForLabel="partner">
    sourcetype=your_sourcetype | fields partner | dedup partner
</populatingSearch>

View solution in original post

ziegfried
Influencer
<populatingSearch fieldForValue="partner" fieldForLabel="partner">
    sourcetype=your_sourcetype | fields partner | dedup partner
</populatingSearch>

mcwomble
Path Finder

Brilliant! That works a treat

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...