Dashboards & Visualizations

Why is 2nd dropdown populated correctly, but events table is not updating?

junmun-chan
Explorer

Hi,

This is a follow-up to my previous question. Now, I am trying to add a second drop-down. The values populated are correct, but my events table is not updating. Is there some errors in my codes?

 

 

    <panel>
      <title>Error Log</title>
      <input type="dropdown" token="ProfileLog" searchWhenChanged="true">
        <label>Module</label>
        <fieldForLabel>ESPACE_NAME</fieldForLabel>
        <fieldForValue>ESPACE_NAME</fieldForValue>
        <search base="baseSearch">
          <query>| stats count by ESPACE_NAME</query>
        </search>
        <choice value="*">All</choice>
        <default>*</default>
        <initialValue>*</initialValue>
      </input>
      <input type="dropdown" token="MessageLog" searchWhenChanged="true">
        <label>Error Message</label>
        <search base="baseSearch">
          <query>| search ESPACE_NAME="$ProfileLog$" | stats count by MESSAGE</query>
        </search>
        <default>*</default>
        <fieldForLabel>MESSAGE</fieldForLabel>
        <fieldForValue>MESSAGE</fieldForValue>
        <choice value="*">All</choice>
        <initialValue>*</initialValue>
      </input>
      <event>
        <search base="baseSearch">
          <query>| search ESPACE_NAME="$ProfileLog$"</query>
        </search>
        <option name="list.drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </event>
    </panel>

 

 

 

Thanks!

Labels (1)
Tags (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

You are missing the use of the MessageLog token in your search in your search panel.

Your search in the final panel should be

<query>| search ESPACE_NAME="$ProfileLog$" MESSAGE=$MessageLog|s$</query>

Note the subtle difference of quoting the token vs using $token|s$ which tells Splunk to quote it correctly for you.

 

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

You are missing the use of the MessageLog token in your search in your search panel.

Your search in the final panel should be

<query>| search ESPACE_NAME="$ProfileLog$" MESSAGE=$MessageLog|s$</query>

Note the subtle difference of quoting the token vs using $token|s$ which tells Splunk to quote it correctly for you.

 

0 Karma

junmun-chan
Explorer

Thank you! it works 😄

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...