Developing for Splunk Enterprise

How do I assign dropdown links in a table with events from two sourcetypes where one of them is an inputlookup and the other one is a regular index search?


For example, the table is like this
time description vendor1
time description vendor2
time description vendor1
When I click vendor1-its a regular index based search. But vendor 2, it should go the search based on inputlookup.
Please help. Thanks

Tags (1)
0 Karma

Esteemed Legend

To build on what @dal said, you would do something like this:

| eval _search_str=if(vendor=="vendor1", "vendor1 SPL here", "vendor2 SPL here")

Then reference _search_str in your drilldown.

0 Karma


You will need to add another, hidden column, which identifies what kind of search it should, and creates the appropriate search language. Here's an answer that describes it a little more fully -

Presumably there will be more than two vendors in your dropdown, so that method will be the most appropriate. If there were only two, then use radio buttons, and have the radio button set the search language.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.