Reporting

Using multiple multiselects in the dashboard panel to perform a search

abhinav_aashish
Explorer

I have 3 sources of data A,B and C and they have some common data.

Source C is an inputlookup.

There are now 2 multiselect fields "INCLUDE Source" AND "EXCLUDE Source". Whichever source I select in "INCLUDE Source" then it should append the searched data into the table accordingly and none of the sources must be excluded unless specified in the "EXCLUDE Source" (i.e by default NONE should be present in the "EXCLUDE Source".)

I want to use this multiselect feature here in splunk in the following way described below:

1.) By default data from all the sources should be appended after each other and duplicates should be removed. (i.e. "INCLUDE Source" must have value ALL AND "EXCLUDE Source" must have NONE.)

2.) Depending upon the order of included fields in "INCLUDE Source" the data should be appended into the table and depending on the data in the "EXCLUDE Source" the data must be removed from the table.

In all cases the duplicates must be removed.


I tried using 3 radio buttons using YES and NO as options but I was not able to get the result.

0 Karma

abhinav_aashish
Explorer

What i was trying to do was to remove those records from the table which were also there in EXCLUDE Sources index.

I have already tried what you mentioned.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Why do you need two multi-selects, if a source is not selected in the INCLUDE multi-select, isn't it by definition EXCLUDED? With one multi-select for INCLUDE, all you would need to do is deal with the ALL case, for which there are a number of options. It would be easier to help if you shared what you have so far, and what your search looks like showing how the tokens are used.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...