Dashboards & Visualizations

Question token being used in input dropdown

Deepz2612
Explorer

Hi all,

I have a query such as below for the input drop down

<input type="dropdown" token="country" searchWhenChanged="true">
        <label>Country</label>
        <fieldForLabel>Country</fieldForLabel>
        <fieldForValue>Country</fieldForValue>
        <default>*</default>
        <initialValue>*</initialValue>
        <search>
          <query>{search}|stats count by Country_Code Country</query>
          <earliest>0</earliest>
          <latest></latest>
        </search>
      </input>

I'm able to pass only the value of Country using the token "country" to the panel.
At times I wanted to make use of Country Code value.
How to set token for Country Code also.

i.e.,when a country is selected from the dropdown its corresponding country codes I wanted to use it for the few panels in the dashboard.

Tags (1)
0 Karma

vnravikumar
Champion

Hi

Try like

<form>
  <label>dropdown</label>
  <fieldset submitButton="false">
    <input type="dropdown" token="field1">
      <label>field1</label>
      <fieldForLabel>code</fieldForLabel>
      <fieldForValue>country</fieldForValue>
      <search>
        <query>| makeresults 
| eval code=1,country="US" 
| append 
    [| makeresults 
    | eval code=2,country="Russia"]</query>
        <earliest>-24h@h</earliest>
        <latest>now</latest>
      </search>
      <change>
        <set token="code">$value$</set>
        <set token="country">$label$</set>
      </change>
    </input>
  </fieldset>
</form>
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...