Reporting

How to get text input in a dashboard to return any result including null by default when assigned to a field in a saved search?

snix
Communicator

I have a dashboard with a text input that is assigned to a field in a saved search with a default * entered into it

Text input example:

<input type="text" token="DashboardInput_UserName" searchWhenChanged="true">
<label>User Name</label>
<default>*</default>
<initialValue>*</initialValue>
</input>

Search Example:

<query>index=iis ExternalUserName="$DashboarInput_UserName$"
</query>

The issue is I want it to by default show me every event but when you use a wildcard * as a default you get everything but null values and I will need the null values as well. Is this possible?

0 Karma
1 Solution

snix
Communicator

Okay looks like I got a workaround that gets the result I am looking for. Instead of trying to find fields with actual values and null values, just fill in the null values with something like a - by using this command:

fillnull value=-

After I did that I was able to find all events by just using *

View solution in original post

0 Karma

snix
Communicator

Okay looks like I got a workaround that gets the result I am looking for. Instead of trying to find fields with actual values and null values, just fill in the null values with something like a - by using this command:

fillnull value=-

After I did that I was able to find all events by just using *

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...