Dashboards & Visualizations

drop down filter issue

Keerthi
Path Finder

Hi, I dont understand the issue . the drop down filter is showing duplicate issues. can anyone pls help me how to resolve?

Keerthi_0-1708858292723.pngKeerthi_1-1708858314123.png

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Keerthi,

in the results of the search you are using to populate the dropdown, there are some duplicated values, so you have to dedup your results fo the field that you're using for displaying.

If you could share your dropdown search I could be more detailed.

Ciao.

Giuseppe

0 Karma

Keerthi
Path Finder

sure , this is what i see in search string inside. pls refer screenshot.

Keerthi_0-1708858928059.png

Keerthi_1-1708858951875.png

pls let me know if you need more information?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Keerthi,

you have to dedup for the firld that you display, in the first search you dedup for two fields. so it could be possible that you have duplicated values for the displayed field.

Insteda in the second search, I don't see any dedup command.

Add a dedup row dedupping for the field to display.

Ciao.

Giuseppe

0 Karma

Keerthi
Path Finder

Hi,
are you telling me to write dedup command again. pls check the screenshot below:

Keerthi_0-1708945981162.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

 @Keerthi ,

you need only the dedup for the field to listù, the other dedup isn't required.

in few words, you should run something like this:

<your_search>
| dedup Time
| sort Time
| table Time

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...