Dashboards & Visualizations

Question token being used in input dropdown

Deepz2612
Explorer

Hi all,

I have a query such as below for the input drop down

<input type="dropdown" token="country" searchWhenChanged="true">
        <label>Country</label>
        <fieldForLabel>Country</fieldForLabel>
        <fieldForValue>Country</fieldForValue>
        <default>*</default>
        <initialValue>*</initialValue>
        <search>
          <query>{search}|stats count by Country_Code Country</query>
          <earliest>0</earliest>
          <latest></latest>
        </search>
      </input>

I'm able to pass only the value of Country using the token "country" to the panel.
At times I wanted to make use of Country Code value.
How to set token for Country Code also.

i.e.,when a country is selected from the dropdown its corresponding country codes I wanted to use it for the few panels in the dashboard.

Tags (1)
0 Karma

vnravikumar
Champion

Hi

Try like

<form>
  <label>dropdown</label>
  <fieldset submitButton="false">
    <input type="dropdown" token="field1">
      <label>field1</label>
      <fieldForLabel>code</fieldForLabel>
      <fieldForValue>country</fieldForValue>
      <search>
        <query>| makeresults 
| eval code=1,country="US" 
| append 
    [| makeresults 
    | eval code=2,country="Russia"]</query>
        <earliest>-24h@h</earliest>
        <latest>now</latest>
      </search>
      <change>
        <set token="code">$value$</set>
        <set token="country">$label$</set>
      </change>
    </input>
  </fieldset>
</form>
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...