Dashboards & Visualizations

Set token in XML dashboard based on result count in scheduled report

sssignals
Path Finder

Hi Splunk community

I have a scheduled report running every 5 mins that ends with "... | stats count". Is there a way based on result count > 0, set token to true in XML dashboard in order to show the panel that depends on the token.

Thanks in advance.

0 Karma

gaurav_maniar
Builder

Hi,

You can add a hidden panel with saved search and use the result count in other search,

<row depends="$hidden$">
    <panel>
      <table>
        <title>Report Name</title>
        <search ref="Saved Search or Alert Name">
          <done>
            <set token="test">$job.resultCount$</set>
          </done>
        </search>
      </table>
    </panel>
  </row>
  <row>
    <panel>
      <table>
        <search>
          <query>| makeresults | eval test=$test$</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
        </search>
      </table>
    </panel>
  </row>

Accept & up-vote the answer if it helps.

happy splunking.....!!!!

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@sssignals

Here, I suggest you store count in any lookup and use in your dashbaord to set token.

Like.

.... | stats count | oputputlookup my_lookup

Access lookup data using | inputlookup my_lookup | table count and set token in the dashboard.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...