Developing for Splunk Enterprise

How do I develop a search query for my dropdown to sync with my table?

Explorer

I am trying to build a dashboard with a table that can be navigated with the dropdown menu.

This is the query for my table:

`source="LMCustomerRevLicense.csv" | dedup "Account Name" | table "Account Name" "Total Active Subscription Revenue _converted"`

What would the search token, search query need to be for the dropdown to search off the Account Names?

0 Karma
1 Solution

Path Finder

Hey Ragate,

Depending on what you set the token value to when creating the drop down you need to add the token into your search like so:

 `source="LMCustomerRevLicense.csv"  $field_tok$ | dedup "Account Name" | table "Account Name" "Total Active Subscription Revenue _converted"`

Reference: http://docs.splunk.com/Documentation/Splunk/7.1.1/Viz/tokens

View solution in original post

Path Finder

Hey Ragate,

Depending on what you set the token value to when creating the drop down you need to add the token into your search like so:

 `source="LMCustomerRevLicense.csv"  $field_tok$ | dedup "Account Name" | table "Account Name" "Total Active Subscription Revenue _converted"`

Reference: http://docs.splunk.com/Documentation/Splunk/7.1.1/Viz/tokens

View solution in original post

Explorer

Thank You!

0 Karma

Path Finder

Dont forget to mark this as the answer

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!