Dashboards & Visualizations

on a dashboard and searchTemplate

asarolkar
Builder

I have one user interactive input from a < form > that needs to go to two searches - wherever it gets a match must display in the form of a table.

I have created a dashboard and can pass in an ID using < searchTemplate> and < fieldset > - basically I pass a token by the name of $ID$ into the search inside the searchTemplate.

However searchTemplate only ever takes in one search - for me there's TWO sourcetypes - if I cannot get this id from Sourcetype A I need to be able to look in Sourcetype B - how would I accomplish that in one form using ONE actual search entry into < searchTemplate> ?

Something like this ---->

< searchtemplate >

sourcetype="A" idInTableA="$ID$"

sourcetype="B" idInTableB="$ID$"

< /searchtemplate >

Any ideas so as to the most sensible way to go about this ?

0 Karma

asarolkar
Builder

That by the way, did not work.

Splunk errors out saying it is unable to parse the search

0 Karma

gkanapathy
Splunk Employee
Splunk Employee
(sourcetype=A idInTableA="$ID$") OR (sourcetype=B idInTableB="$ID$")

?

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...