Dashboards & Visualizations

label usage in dashboard

pipipipi
Path Finder

Hi all,

I have dropdown input in my dashboard.

    <input type="dropdown" token="test" searchWhenChanged="false">
    <label>test</label>
    <choice value="hogehogehoge">ALL</choice>
    <choice value="hogehogehoge">ALL2</choice>
    <choice value="hogehogehoge">ALL3</choice>
    <default>ALL</default>
    <prefix>(</prefix>
    <suffix>)</suffix>
    <change>
    <set token="label1">$label$</set>
</change>

I want use label value(like ALL, ALL2, ALL3) in my base search.
(this is example)

|makeresult 
[|eval test1="$label1$"]

but this eval command has no value.
How to get $label$ in eval command?

Thank you for helping me.

0 Karma

to4kawa
Ultra Champion
<form>
  <label>dropdown</label>
  <search id="base">
    <query>
         |makeresults 
   |eval command="sendmail"
      </query>
  </search>
  <fieldset submitButton="false">
    <input type="dropdown" token="test" searchWhenChanged="true">
      <label>test</label>
      <choice value="hogehogehoge1">ALL</choice>
      <choice value="hogehogehoge2">ALL2</choice>
      <choice value="hogehogehoge3">ALL3</choice>
      <default>ALL</default>
      <prefix>(</prefix>
      <suffix>)</suffix>
      <change>
        <set token="label1">$label$</set>
      </change>
    </input>
  </fieldset>
  <row>
    <panel>
      <table>
        <search base="base">
          <query>|eval to="hogehoge", subject="test", message="select is $label1$"</query>
        </search>
        <option name="refresh.display">progressbar</option>
      </table>
    </panel>
  </row>
</form>

How about this?

0 Karma

vnravikumar
Champion

Hi

Can you please check the below code and let me know what issues are you facing.

<form>
  <label>dropdown</label>
  <search id="base">
    <query>
       |makeresults 
 |eval test1="$label1$"
    </query>
  </search>
  <fieldset submitButton="false">
    <input type="dropdown" token="test" searchWhenChanged="true">
      <label>test</label>
      <choice value="hogehogehoge1">ALL</choice>
      <choice value="hogehogehoge2">ALL2</choice>
      <choice value="hogehogehoge3">ALL3</choice>
      <default>ALL</default>
      <prefix>(</prefix>
      <suffix>)</suffix>
      <change>
        <set token="label1">$label$</set>
      </change>
    </input>
  </fieldset>
  <row>
    <panel>
      <table>
        <search base="base">

        </search>
      </table>
    </panel>
  </row>
</form>
0 Karma

pipipipi
Path Finder

Thank you for helping me.

  <form>
   <label>dropdown</label>
   <search id="base">
     <query>
        |makeresults 
  |eval test1="$label1$"
     </query>
   </search>
<search base="base"><query>
    |sendemail to="hogehoge" subject="test" message="select is $result.test1$"</query></search>
   <fieldset submitButton="true" autoRun="true">
     <input type="dropdown" token="test" searchWhenChanged="false>
       <label>test</label>
       <choice value="hogehogehoge1">ALL</choice>
       <choice value="hogehogehoge2">ALL2</choice>
       <choice value="hogehogehoge3">ALL3</choice>
       <default>ALL</default>
       <prefix>(</prefix>
       <suffix>)</suffix>
       <change>
         <set token="label1">$label$</set>
       </change>
     </input>
   </fieldset>
 </form>

I want to put label value in my email message, but there is no value in my message.
if I put message="select is $label1$"
sendemail command execute twice.

0 Karma

vnravikumar
Champion

You can directly access the token label1, right without base search?

0 Karma

pipipipi
Path Finder

I think so.
if I put message="select is $label1$", email message is select is ALL.
(but I recieve 2 emails.....)

0 Karma

vnravikumar
Champion

can you make autoRun="false" and try it

0 Karma

pipipipi
Path Finder

It does not work.
When I remove $label$
Just 1 email. I have no idea,

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...