Splunk Dev

How do I develop a search query for my dropdown to sync with my table?

Ragate
Explorer

I am trying to build a dashboard with a table that can be navigated with the dropdown menu.

This is the query for my table:

`source="LMCustomerRevLicense.csv" | dedup "Account Name" | table "Account Name" "Total Active Subscription Revenue _converted"`

What would the search token, search query need to be for the dropdown to search off the Account Names?

0 Karma
1 Solution

hos_2
Path Finder

Hey Ragate,

Depending on what you set the token value to when creating the drop down you need to add the token into your search like so:

 `source="LMCustomerRevLicense.csv"  $field_tok$ | dedup "Account Name" | table "Account Name" "Total Active Subscription Revenue _converted"`

Reference: http://docs.splunk.com/Documentation/Splunk/7.1.1/Viz/tokens

View solution in original post

hos_2
Path Finder

Hey Ragate,

Depending on what you set the token value to when creating the drop down you need to add the token into your search like so:

 `source="LMCustomerRevLicense.csv"  $field_tok$ | dedup "Account Name" | table "Account Name" "Total Active Subscription Revenue _converted"`

Reference: http://docs.splunk.com/Documentation/Splunk/7.1.1/Viz/tokens

Ragate
Explorer

Thank You!

0 Karma

Moreilly97
Path Finder

Dont forget to mark this as the answer

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...