Dashboards & Visualizations

Tokens, Searches, User data populuation?

antifreke
Path Finder

So, I'm having some tinkering issues and I wanted to see if I could get some assistance on this. What I have for my idea is the following:
Input bar (User ID)
Dashboard panel (VPN LOGS) | Dashboard panel (Antivirus LOGS)
Dashboard panel (AD Badge LOGS) | Dashboard panel (AD Last Login logs)

I have each of the searches setup in the Dashboards, but I'm having issues feeding that custom input bar down to those panels.

Ideally, I'd enter a username.. SmithMi and it would populate those 4 dashboard panels with his data.


Input Bar
Token = UID_tok
Default = Enter User ID

dashboard panel
index="vpnlogs_*" token="UID_tok" | table user src_country_name

Am I feeding this incorrectly?

0 Karma

juvetm
Communicator

pl can u send me the code through this mail juvet45@yahoo.com i can help you this problem

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...