Splunk Dev

How do I assign dropdown links in a table with events from two sourcetypes where one of them is an inputlookup and the other one is a regular index search?

Aishwaryagirish
Engager

For example, the table is like this
time description vendor1
time description vendor2
time description vendor1
When I click vendor1-its a regular index based search. But vendor 2, it should go the search based on inputlookup.
Please help. Thanks

Tags (1)
0 Karma

woodcock
Esteemed Legend

To build on what @dal said, you would do something like this:

| eval _search_str=if(vendor=="vendor1", "vendor1 SPL here", "vendor2 SPL here")

Then reference _search_str in your drilldown.

0 Karma

DalJeanis
Legend

You will need to add another, hidden column, which identifies what kind of search it should, and creates the appropriate search language. Here's an answer that describes it a little more fully -

https://answers.splunk.com/answers/26825/drilldown-from-a-hidden-column.html

Presumably there will be more than two vendors in your dropdown, so that method will be the most appropriate. If there were only two, then use radio buttons, and have the radio button set the search language.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...