Dashboards & Visualizations

Splunk works in search but not in dashboard dropdown

super_edition
Path Finder

Hello Everyone,

My below splunk query works fine in normal splunk search and it returns expected results:

 

index="my_index" 
| stats count by kubernetes_cluster | table kubernetes_cluster | sort kubernetes_cluster

 

However when the same query when I have it in dashboard's dropdown it is not returning that data.

Search on Change is unchecked.

super_edition_0-1728296935819.png

the dropdown looks like this:

super_edition_0-1728297151041.png

source view:

 <input type="dropdown" token="regions" searchWhenChanged="false">
      <label>region</label>
      <fieldForLabel>regions</fieldForLabel>
      <fieldForValue>regions</fieldForValue>
      <search>
        <query>index="my_index" 
| stats count by kubernetes_cluster | table kubernetes_cluster | sort kubernetes_cluster</query>
        <earliest>0</earliest>
        <latest></latest>
      </search>
    </input>

 

 

Labels (1)
Tags (4)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @super_edition ,

the only field present in your search is "kubernetes_cluster" but the field in Label and value is "region".

use the same field.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @super_edition ,

the only field present in your search is "kubernetes_cluster" but the field in Label and value is "region".

use the same field.

Ciao.

Giuseppe

super_edition
Path Finder

Thanks. It worked

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...