Splunk Dev

Can you set token with multiple values?

Thenmozhi1
Engager

Hi,

I am trying to change/control many multi-select dropdowns by one Master_multi-select dropdown value/checks.

So I am trying to use more than one value in the set-token tag. But it is not working, if I give 2 values in the Set-token tag. then it will get merge but if I give a single value then it is working fine.

I tried multiple ways like double quotes, single quotes, and many symbols, but I could not find the solution.

 

Please find the below example and help me to find a solution.

 

<set token="form.Filter1"> "rejected" , "new" </set>

out put will be like below. 

Thenmozhi1_0-1633281655240.pngThenmozhi1_0-1633281655240.png

 

But the expectation is like below

Thenmozhi1_1-1633281655325.pngThenmozhi1_1-1633281655325.png

 

 

Example in multiselect code:-

<input type="dropdown" token="MasterFilter_Token">
<label>MasterFilter</label>
...,

<change>
<condition>

<set token="form.Filter1"> "new", "rejected", "closed" </set>

...,

</condition>
</change>

...,

 

@token1 @Anonymous @splunk 

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Rather than set try using eval and split to return a multi-value field

<eval token="form.Filter1">split("rejected,new",",")</eval>

 

View solution in original post

Thenmozhi1
Engager

Hi,

It is working fine.

Thanks a lot for your valuable support and help !!! 😊 

ITWhisperer
SplunkTrust
SplunkTrust

Rather than set try using eval and split to return a multi-value field

<eval token="form.Filter1">split("rejected,new",",")</eval>

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...