Dashboards & Visualizations

Why is 2nd dropdown populated correctly, but events table is not updating?

junmun-chan
Explorer

Hi,

This is a follow-up to my previous question. Now, I am trying to add a second drop-down. The values populated are correct, but my events table is not updating. Is there some errors in my codes?

 

 

    <panel>
      <title>Error Log</title>
      <input type="dropdown" token="ProfileLog" searchWhenChanged="true">
        <label>Module</label>
        <fieldForLabel>ESPACE_NAME</fieldForLabel>
        <fieldForValue>ESPACE_NAME</fieldForValue>
        <search base="baseSearch">
          <query>| stats count by ESPACE_NAME</query>
        </search>
        <choice value="*">All</choice>
        <default>*</default>
        <initialValue>*</initialValue>
      </input>
      <input type="dropdown" token="MessageLog" searchWhenChanged="true">
        <label>Error Message</label>
        <search base="baseSearch">
          <query>| search ESPACE_NAME="$ProfileLog$" | stats count by MESSAGE</query>
        </search>
        <default>*</default>
        <fieldForLabel>MESSAGE</fieldForLabel>
        <fieldForValue>MESSAGE</fieldForValue>
        <choice value="*">All</choice>
        <initialValue>*</initialValue>
      </input>
      <event>
        <search base="baseSearch">
          <query>| search ESPACE_NAME="$ProfileLog$"</query>
        </search>
        <option name="list.drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </event>
    </panel>

 

 

 

Thanks!

Labels (1)
Tags (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

You are missing the use of the MessageLog token in your search in your search panel.

Your search in the final panel should be

<query>| search ESPACE_NAME="$ProfileLog$" MESSAGE=$MessageLog|s$</query>

Note the subtle difference of quoting the token vs using $token|s$ which tells Splunk to quote it correctly for you.

 

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

You are missing the use of the MessageLog token in your search in your search panel.

Your search in the final panel should be

<query>| search ESPACE_NAME="$ProfileLog$" MESSAGE=$MessageLog|s$</query>

Note the subtle difference of quoting the token vs using $token|s$ which tells Splunk to quote it correctly for you.

 

0 Karma

junmun-chan
Explorer

Thank you! it works 😄

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...