Reporting

Using multiple multiselects in the dashboard panel to perform a search

abhinav_aashish
Explorer

I have 3 sources of data A,B and C and they have some common data.

Source C is an inputlookup.

There are now 2 multiselect fields "INCLUDE Source" AND "EXCLUDE Source". Whichever source I select in "INCLUDE Source" then it should append the searched data into the table accordingly and none of the sources must be excluded unless specified in the "EXCLUDE Source" (i.e by default NONE should be present in the "EXCLUDE Source".)

I want to use this multiselect feature here in splunk in the following way described below:

1.) By default data from all the sources should be appended after each other and duplicates should be removed. (i.e. "INCLUDE Source" must have value ALL AND "EXCLUDE Source" must have NONE.)

2.) Depending upon the order of included fields in "INCLUDE Source" the data should be appended into the table and depending on the data in the "EXCLUDE Source" the data must be removed from the table.

In all cases the duplicates must be removed.


I tried using 3 radio buttons using YES and NO as options but I was not able to get the result.

0 Karma

abhinav_aashish
Explorer

What i was trying to do was to remove those records from the table which were also there in EXCLUDE Sources index.

I have already tried what you mentioned.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Why do you need two multi-selects, if a source is not selected in the INCLUDE multi-select, isn't it by definition EXCLUDED? With one multi-select for INCLUDE, all you would need to do is deal with the ALL case, for which there are a number of options. It would be easier to help if you shared what you have so far, and what your search looks like showing how the tokens are used.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...