Dashboards & Visualizations

Why is dashboard drop-down unable to use index field host in dynamic list for drop-down?

tmmclau
New Member

I am trying to add a dropdown in a Dashboard in Splunk cloud using the index field host from a metric dataset. I want the host field to dynamically update the dropdown from the host field available in the dataset at any one time.  I am using the search for the data source of the dropdown as '|mcatalog values(host) where index=em_metrics | mvexpand values(host)'.  All other settings on the drop down are the defaults.  I have tried changing the search several times and have been unable to get it to work.  Any suggestions would be greatly appreciated.  

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...