Dashboards & Visualizations

if then else dashboard help

sgro777
Engager

I'm very new to Splunk.  I have two tokens as input to a dashboard and want to change a query based on which one is entered.  

My base query (with no dashboard) 

eventtype=builder user_id IN (<value1>, <value2>, etc.) | eval .....

I created a dashboard and want to use tokens for the input.  

token1=$id$
token2=$email$


If the token1 has data, I want to execute

eventtype=builder user_id IN ($id$) | eval....

 otherwise, I want to execute 

eventtype=builder user_mail in $email$ | eval .....

 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @sgro777 ,

sorry, my error, please try:

eventtype=builder (user_id IN ($id$) OR user_mail IN ($email$))
| eval ...

Ciao.

Giuseppe

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Your issue may be to do with what you do if the user has not selected a value for either token. A dashboard would normal wait for the user to make a selection. Handling tokens is easier in Classic SimpleXML dashboards than currently available in Studio. Is this an option for you?

0 Karma

sgro777
Engager

If I can't figure it out, I'll try the simple dashboard.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sgro777 ,

did you tried with:

eventtype=builder (user_id IN ($id$) OR user_mail in $email$)
| eval .....

?

Ciao.

Giuseppe

0 Karma

sgro777
Engager

I tried this but it would not work. 

eventtype=builder (user_id IN ($id$) OR user_mail in $email$)
| eval .....

 

I also tried eventtype=builder ((user_id IN ($id$) OR (user_mail IN ($email$))) | eval ... but that only works if both tokens are populated.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sgro777 ,

sorry, my error, please try:

eventtype=builder (user_id IN ($id$) OR user_mail IN ($email$))
| eval ...

Ciao.

Giuseppe

0 Karma

sgro777
Engager

THANK YOU!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sgro777 ,

good for you, see next time!

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated by all the Contributors 😉

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...