Security

Form error when referencing a token in the search

cbbrown
New Member

I have three multi-selection options for my form. All three default to *, but the main panel of the form throws an error when I reference one or all of the token values to filter the search down. I get the following error: Error in 'search' command unable to parse the search: Comparator '=' has an invalid term on the right hand side.

The search string for the panel calling the token is as follows:

| dbxquery output='csv' connection="blah" query="SELECT * FROM "blah_data"
| search filtering_field=$filter_tok$
| table field1 field2 field3

The Multi-selection input is defined as follows:

Label: Filtering Field
Token Options
Token: filter_tok
Default: All
Token Prefix: (
Token Suffix: )
Token Value Prefix: Filtering_Field="
Token Value Suffix= "
Delimiter: OR (spaces before and after OR)
Static Options
Name: All
Value: *

Dynamic Options
Search String:
| dbxquery output='csv' connection="blah" query="SELECT * FROM "blah_data"
| dedup filtering_field
| table filtering_field

Time Input: Last 24 Hours
Field For Label: Filtering_Field
Field of Value: Filtering_Field

Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...