Dashboards & Visualizations

Use eval to reference a $token$

mansel_scheffel
Explorer

Hi,

I have a dashboard that is populated by an input.. It selects the index.. I am using the following search based on that to populate a dashboard:

index=_internal source=license_usage.log type=Usage pool= | stats sum(b) as b by idx | eval GB's=round((b) /1000/1000/1000,2) | rename idx as Index | fields Index GB's | sort 20 - GB's

I want it to select whichever index the user chooses in the input.. So I need to use eval to make idx=$index_name$ or something to reference the right idx from the log by using the input dropdown.

Any thoughts?

Thanks,

0 Karma
1 Solution

DMohn
Motivator

If I get it correct you want to be able to have the user to select a value from a input field (dropdown, etc) and then limit the results of your search to the selected value for idx?

First, you should create a input, that only lets the user select valid fields for idx. In your case (internal license usage) this would be the following XML code for a dropdown selector:

 <input type="dropdown" token="token_idx">
  <label>IDX</label>
  <search>
    <query>index=_internal source=*license_usage.log | fields idx | dedup idx</query>
  </search>
  <fieldForLabel>idx</fieldForLabel>
  <fieldForValue>idx</fieldForValue>
 </input>

Then you can integrate the selected value by integrating the $token_idx$ token into your search:

 index=_internal source=*license_usage.log type=Usage idx=$token_idx$| stats sum(b) as b by idx | eval GB's=round((b) /1000/1000/1000,2) | rename idx as Index | fields Index GB's | sort 20 - GB's

View solution in original post

0 Karma

DMohn
Motivator

If I get it correct you want to be able to have the user to select a value from a input field (dropdown, etc) and then limit the results of your search to the selected value for idx?

First, you should create a input, that only lets the user select valid fields for idx. In your case (internal license usage) this would be the following XML code for a dropdown selector:

 <input type="dropdown" token="token_idx">
  <label>IDX</label>
  <search>
    <query>index=_internal source=*license_usage.log | fields idx | dedup idx</query>
  </search>
  <fieldForLabel>idx</fieldForLabel>
  <fieldForValue>idx</fieldForValue>
 </input>

Then you can integrate the selected value by integrating the $token_idx$ token into your search:

 index=_internal source=*license_usage.log type=Usage idx=$token_idx$| stats sum(b) as b by idx | eval GB's=round((b) /1000/1000/1000,2) | rename idx as Index | fields Index GB's | sort 20 - GB's
0 Karma

mansel_scheffel
Explorer

Thanks exactly what I needed!

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...