Splunk Dev

Can you set token with multiple values?

Thenmozhi1
Engager

Hi,

I am trying to change/control many multi-select dropdowns by one Master_multi-select dropdown value/checks.

So I am trying to use more than one value in the set-token tag. But it is not working, if I give 2 values in the Set-token tag. then it will get merge but if I give a single value then it is working fine.

I tried multiple ways like double quotes, single quotes, and many symbols, but I could not find the solution.

 

Please find the below example and help me to find a solution.

 

<set token="form.Filter1"> "rejected" , "new" </set>

out put will be like below. 

Thenmozhi1_0-1633281655240.png

 

But the expectation is like below

Thenmozhi1_1-1633281655325.png

 

 

Example in multiselect code:-

<input type="dropdown" token="MasterFilter_Token">
<label>MasterFilter</label>
...,

<change>
<condition>

<set token="form.Filter1"> "new", "rejected", "closed" </set>

...,

</condition>
</change>

...,

 

@token1 @Anonymous @splunk 

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Rather than set try using eval and split to return a multi-value field

<eval token="form.Filter1">split("rejected,new",",")</eval>

 

View solution in original post

Thenmozhi1
Engager

Hi,

It is working fine.

Thanks a lot for your valuable support and help !!! 😊 

ITWhisperer
SplunkTrust
SplunkTrust

Rather than set try using eval and split to return a multi-value field

<eval token="form.Filter1">split("rejected,new",",")</eval>

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...