Dashboards & Visualizations

Using a field value twice while building a multi-select input token

shikhanshua
Explorer

I have a multi-select like this:

 

 

    <input token="name" type="multiselect">
      <label>Name</label>
      <choice value="*">ALL</choice>
      <prefix>(</prefix>
      <suffix>)</suffix>
      <valuePrefix>name="</valuePrefix>
      <valueSuffix>"</valueSuffix>
      <delimiter> OR </delimiter>
      <fieldForLabel>name</fieldForLabel>
      <fieldForValue>name</fieldForValue>
      <search>
        <query>index=my_index | dedup name | sort name</query>
      </search>
    </input>

 

 

It correctly produces a token $name$ with value:

 

 

(name="VALUE1" OR name="VALUE2" ... )

 

 

 

But I have a need to make the token look like:

 

 

(name="VALUE1" OR name="VALUE1.*" OR name="VALUE2" OR name="VALUE2.*" ... )

 

 

because if "VALUE1" is selected in the multi-select, I want events that match both "VALUE1" and "VALUE1.*" (note the dot star, not just star).

 

But I cannot just match "VALUE1*" as that will bring in events that have a different value which BEGINS with "VALUE1" which I don't want.

 

So the question is - how can I utilize the values TWICE in the token generation? I can't wrap my head around how I might be able to achieve this.

Labels (2)
0 Karma
1 Solution

marnall
Motivator

This should produce an equivalent token value:

 

 

<input token="name" type="multiselect">
<label>Name</label>
<choice value="*">ALL</choice>
<prefix>(</prefix>
<suffix>)</suffix>
<valuePrefix>name IN ("</valuePrefix>
<valueSuffix>")</valueSuffix>
<delimiter> OR </delimiter>
<fieldForLabel>name</fieldForLabel>
<fieldForValue>val</fieldForValue>
<search>
<query>index=my_index | dedup name | sort name
| eval val = name+"\",\""+name+".*"</query>
</search>
</input>

 

 


This will produce token values like:

 

 

(name IN ("VALUE1","VALUE1.*") OR name IN ("VALUE2","VALUE2.*") ...)

 

 


Which are equivalent to

 

 

(name="VALUE1" OR name="VALUE1.*" OR name="VALUE2" OR name="VALUE2.*" ... )

 

 

 

EDIT: 

Now that I think about it, you can make exactly that token value by doing this:

 

<input token="name" type="multiselect">
      <label>Name</label>
      <choice value="*">ALL</choice>
      <prefix>(</prefix>
      <suffix>)</suffix>
      <valuePrefix></valuePrefix>
      <valueSuffix></valueSuffix>
      <delimiter> OR </delimiter>
      <fieldForLabel>name</fieldForLabel>
      <fieldForValue>val</fieldForValue>
      <search>
        <query>index=my_index | dedup name | sort name
| eval val = "name=\""+name+"\" OR name=\""+name+".*\""</query>
      </search>
    </input>

 

View solution in original post

shikhanshua
Explorer

Genius! Works perfectly!

0 Karma

marnall
Motivator

This should produce an equivalent token value:

 

 

<input token="name" type="multiselect">
<label>Name</label>
<choice value="*">ALL</choice>
<prefix>(</prefix>
<suffix>)</suffix>
<valuePrefix>name IN ("</valuePrefix>
<valueSuffix>")</valueSuffix>
<delimiter> OR </delimiter>
<fieldForLabel>name</fieldForLabel>
<fieldForValue>val</fieldForValue>
<search>
<query>index=my_index | dedup name | sort name
| eval val = name+"\",\""+name+".*"</query>
</search>
</input>

 

 


This will produce token values like:

 

 

(name IN ("VALUE1","VALUE1.*") OR name IN ("VALUE2","VALUE2.*") ...)

 

 


Which are equivalent to

 

 

(name="VALUE1" OR name="VALUE1.*" OR name="VALUE2" OR name="VALUE2.*" ... )

 

 

 

EDIT: 

Now that I think about it, you can make exactly that token value by doing this:

 

<input token="name" type="multiselect">
      <label>Name</label>
      <choice value="*">ALL</choice>
      <prefix>(</prefix>
      <suffix>)</suffix>
      <valuePrefix></valuePrefix>
      <valueSuffix></valueSuffix>
      <delimiter> OR </delimiter>
      <fieldForLabel>name</fieldForLabel>
      <fieldForValue>val</fieldForValue>
      <search>
        <query>index=my_index | dedup name | sort name
| eval val = "name=\""+name+"\" OR name=\""+name+".*\""</query>
      </search>
    </input>

 

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...