Monitoring Splunk

How to use the output of the base query in the Input panel as dropdown ?

Real_captain
Path Finder

Hi Team 

Is it possible to use the output value of the base query as the drop down values in the input panel. 

Example : 

<search id="base">
<!-- Master query which will be used in all the Panels -->
<query>index=ABC | eval fieldA =  If (fieldB = "ABC" ,  fieldB , fieldA )</query>

I want to use the value of the fieldA in the dropdown of the input POH_Group. Below query is not working and i am not getting the values of fieldA in the dropdown of POH_Group:

<input type="dropdown" token="POH_tokenD" searchWhenChanged="true">
<label>POH_Group</label>
<prefix>POH_Group1="</prefix>
<suffix>"</suffix>
<fieldForLabel>POH_Group1</fieldForLabel>
<fieldForValue>POH_Group1</fieldForValue>
<choice value="*">All</choice>
<default>*</default>
<search>
<query> | dedup fieldA | table fieldA
</query>

 

Can you please help to fix this issue. 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Real_captain ,

when you use a base search, you have to call it in the search tag:

<search base="your_base_search">

Ciao.

Giuseppe

View solution in original post

0 Karma

Real_captain
Path Finder

@gcusello : 
I want to use FieldA : 

Will the below query works?? 

<input type="dropdown" token="POH_tokenD" searchWhenChanged="true">
<label>POH_Group</label>
<prefix>POH_Group1="</prefix>
<suffix>"</suffix>
<fieldForLabel>fieldA</fieldForLabel>
<fieldForValue>fieldA</fieldForValue>
<choice value="*">All</choice>
<default>*</default>
<search>
<query> | dedup fieldA | table fieldA
</query>
0 Karma

Real_captain
Path Finder

HI @gcusello 
After using the correct fieldForLabel , i am not able to fetch the result in the dropdown using the dynamic query: 

Query :  Field POH_Group1 is fetched by the base query present on the top with the  <search id="base">

<input type="dropdown" token="POH_token" depends="$POH_input$" searchWhenChanged="true">
<label>POH_Group</label>
<fieldForLabel>POH_Group1</fieldForLabel>
<fieldForValue>POH_Group1</fieldForValue>
<choice value="*">All</choice>
<default>*</default>
<search>
<query>| dedup POH_Group1 | table POH_Group1</query>
<earliest>-30d@d</earliest>
<latest>now</latest>
</search>
</input>



Real_captain_0-1729084043047.png

 



0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Real_captain ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Real_captain ,

when you use a base search, you have to call it in the search tag:

<search base="your_base_search">

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Real_captain ,

if fieldA is extracted for the data set, in this way you can use it.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Real_captain ,

there an error: in the input search you have as output only the fieldA field, but in the FieldForLabel and FieldForValue tags you want to use the POH_Group1 field that isn't in the input search outputs.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...