Reporting

How to get text input in a dashboard to return any result including null by default when assigned to a field in a saved search?

snix
Communicator

I have a dashboard with a text input that is assigned to a field in a saved search with a default * entered into it

Text input example:

<input type="text" token="DashboardInput_UserName" searchWhenChanged="true">
<label>User Name</label>
<default>*</default>
<initialValue>*</initialValue>
</input>

Search Example:

<query>index=iis ExternalUserName="$DashboarInput_UserName$"
</query>

The issue is I want it to by default show me every event but when you use a wildcard * as a default you get everything but null values and I will need the null values as well. Is this possible?

0 Karma
1 Solution

snix
Communicator

Okay looks like I got a workaround that gets the result I am looking for. Instead of trying to find fields with actual values and null values, just fill in the null values with something like a - by using this command:

fillnull value=-

After I did that I was able to find all events by just using *

View solution in original post

0 Karma

snix
Communicator

Okay looks like I got a workaround that gets the result I am looking for. Instead of trying to find fields with actual values and null values, just fill in the null values with something like a - by using this command:

fillnull value=-

After I did that I was able to find all events by just using *

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...