Reporting

Using multiple multiselects in the dashboard panel to perform a search

abhinav_aashish
Explorer

I have 3 sources of data A,B and C and they have some common data.

Source C is an inputlookup.

There are now 2 multiselect fields "INCLUDE Source" AND "EXCLUDE Source". Whichever source I select in "INCLUDE Source" then it should append the searched data into the table accordingly and none of the sources must be excluded unless specified in the "EXCLUDE Source" (i.e by default NONE should be present in the "EXCLUDE Source".)

I want to use this multiselect feature here in splunk in the following way described below:

1.) By default data from all the sources should be appended after each other and duplicates should be removed. (i.e. "INCLUDE Source" must have value ALL AND "EXCLUDE Source" must have NONE.)

2.) Depending upon the order of included fields in "INCLUDE Source" the data should be appended into the table and depending on the data in the "EXCLUDE Source" the data must be removed from the table.

In all cases the duplicates must be removed.


I tried using 3 radio buttons using YES and NO as options but I was not able to get the result.

Labels (1)
0 Karma

abhinav_aashish
Explorer

What i was trying to do was to remove those records from the table which were also there in EXCLUDE Sources index.

I have already tried what you mentioned.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Why do you need two multi-selects, if a source is not selected in the INCLUDE multi-select, isn't it by definition EXCLUDED? With one multi-select for INCLUDE, all you would need to do is deal with the ALL case, for which there are a number of options. It would be easier to help if you shared what you have so far, and what your search looks like showing how the tokens are used.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...