Dashboards & Visualizations

Why is 2nd dropdown populated correctly, but events table is not updating?

junmun-chan
Explorer

Hi,

This is a follow-up to my previous question. Now, I am trying to add a second drop-down. The values populated are correct, but my events table is not updating. Is there some errors in my codes?

 

 

    <panel>
      <title>Error Log</title>
      <input type="dropdown" token="ProfileLog" searchWhenChanged="true">
        <label>Module</label>
        <fieldForLabel>ESPACE_NAME</fieldForLabel>
        <fieldForValue>ESPACE_NAME</fieldForValue>
        <search base="baseSearch">
          <query>| stats count by ESPACE_NAME</query>
        </search>
        <choice value="*">All</choice>
        <default>*</default>
        <initialValue>*</initialValue>
      </input>
      <input type="dropdown" token="MessageLog" searchWhenChanged="true">
        <label>Error Message</label>
        <search base="baseSearch">
          <query>| search ESPACE_NAME="$ProfileLog$" | stats count by MESSAGE</query>
        </search>
        <default>*</default>
        <fieldForLabel>MESSAGE</fieldForLabel>
        <fieldForValue>MESSAGE</fieldForValue>
        <choice value="*">All</choice>
        <initialValue>*</initialValue>
      </input>
      <event>
        <search base="baseSearch">
          <query>| search ESPACE_NAME="$ProfileLog$"</query>
        </search>
        <option name="list.drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </event>
    </panel>

 

 

 

Thanks!

Labels (1)
Tags (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

You are missing the use of the MessageLog token in your search in your search panel.

Your search in the final panel should be

<query>| search ESPACE_NAME="$ProfileLog$" MESSAGE=$MessageLog|s$</query>

Note the subtle difference of quoting the token vs using $token|s$ which tells Splunk to quote it correctly for you.

 

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

You are missing the use of the MessageLog token in your search in your search panel.

Your search in the final panel should be

<query>| search ESPACE_NAME="$ProfileLog$" MESSAGE=$MessageLog|s$</query>

Note the subtle difference of quoting the token vs using $token|s$ which tells Splunk to quote it correctly for you.

 

0 Karma

junmun-chan
Explorer

Thank you! it works 😄

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...