Dashboards & Visualizations

Using a field value twice while building a multi-select input token

shikhanshua
Explorer

I have a multi-select like this:

 

 

    <input token="name" type="multiselect">
      <label>Name</label>
      <choice value="*">ALL</choice>
      <prefix>(</prefix>
      <suffix>)</suffix>
      <valuePrefix>name="</valuePrefix>
      <valueSuffix>"</valueSuffix>
      <delimiter> OR </delimiter>
      <fieldForLabel>name</fieldForLabel>
      <fieldForValue>name</fieldForValue>
      <search>
        <query>index=my_index | dedup name | sort name</query>
      </search>
    </input>

 

 

It correctly produces a token $name$ with value:

 

 

(name="VALUE1" OR name="VALUE2" ... )

 

 

 

But I have a need to make the token look like:

 

 

(name="VALUE1" OR name="VALUE1.*" OR name="VALUE2" OR name="VALUE2.*" ... )

 

 

because if "VALUE1" is selected in the multi-select, I want events that match both "VALUE1" and "VALUE1.*" (note the dot star, not just star).

 

But I cannot just match "VALUE1*" as that will bring in events that have a different value which BEGINS with "VALUE1" which I don't want.

 

So the question is - how can I utilize the values TWICE in the token generation? I can't wrap my head around how I might be able to achieve this.

Labels (2)
0 Karma
1 Solution

marnall
Motivator

This should produce an equivalent token value:

 

 

<input token="name" type="multiselect">
<label>Name</label>
<choice value="*">ALL</choice>
<prefix>(</prefix>
<suffix>)</suffix>
<valuePrefix>name IN ("</valuePrefix>
<valueSuffix>")</valueSuffix>
<delimiter> OR </delimiter>
<fieldForLabel>name</fieldForLabel>
<fieldForValue>val</fieldForValue>
<search>
<query>index=my_index | dedup name | sort name
| eval val = name+"\",\""+name+".*"</query>
</search>
</input>

 

 


This will produce token values like:

 

 

(name IN ("VALUE1","VALUE1.*") OR name IN ("VALUE2","VALUE2.*") ...)

 

 


Which are equivalent to

 

 

(name="VALUE1" OR name="VALUE1.*" OR name="VALUE2" OR name="VALUE2.*" ... )

 

 

 

EDIT: 

Now that I think about it, you can make exactly that token value by doing this:

 

<input token="name" type="multiselect">
      <label>Name</label>
      <choice value="*">ALL</choice>
      <prefix>(</prefix>
      <suffix>)</suffix>
      <valuePrefix></valuePrefix>
      <valueSuffix></valueSuffix>
      <delimiter> OR </delimiter>
      <fieldForLabel>name</fieldForLabel>
      <fieldForValue>val</fieldForValue>
      <search>
        <query>index=my_index | dedup name | sort name
| eval val = "name=\""+name+"\" OR name=\""+name+".*\""</query>
      </search>
    </input>

 

View solution in original post

shikhanshua
Explorer

Genius! Works perfectly!

0 Karma

marnall
Motivator

This should produce an equivalent token value:

 

 

<input token="name" type="multiselect">
<label>Name</label>
<choice value="*">ALL</choice>
<prefix>(</prefix>
<suffix>)</suffix>
<valuePrefix>name IN ("</valuePrefix>
<valueSuffix>")</valueSuffix>
<delimiter> OR </delimiter>
<fieldForLabel>name</fieldForLabel>
<fieldForValue>val</fieldForValue>
<search>
<query>index=my_index | dedup name | sort name
| eval val = name+"\",\""+name+".*"</query>
</search>
</input>

 

 


This will produce token values like:

 

 

(name IN ("VALUE1","VALUE1.*") OR name IN ("VALUE2","VALUE2.*") ...)

 

 


Which are equivalent to

 

 

(name="VALUE1" OR name="VALUE1.*" OR name="VALUE2" OR name="VALUE2.*" ... )

 

 

 

EDIT: 

Now that I think about it, you can make exactly that token value by doing this:

 

<input token="name" type="multiselect">
      <label>Name</label>
      <choice value="*">ALL</choice>
      <prefix>(</prefix>
      <suffix>)</suffix>
      <valuePrefix></valuePrefix>
      <valueSuffix></valueSuffix>
      <delimiter> OR </delimiter>
      <fieldForLabel>name</fieldForLabel>
      <fieldForValue>val</fieldForValue>
      <search>
        <query>index=my_index | dedup name | sort name
| eval val = "name=\""+name+"\" OR name=\""+name+".*\""</query>
      </search>
    </input>

 

Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...