Splunk Dev

How do I develop a search query for my dropdown to sync with my table?

Ragate
Explorer

I am trying to build a dashboard with a table that can be navigated with the dropdown menu.

This is the query for my table:

`source="LMCustomerRevLicense.csv" | dedup "Account Name" | table "Account Name" "Total Active Subscription Revenue _converted"`

What would the search token, search query need to be for the dropdown to search off the Account Names?

0 Karma
1 Solution

hos_2
Path Finder

Hey Ragate,

Depending on what you set the token value to when creating the drop down you need to add the token into your search like so:

 `source="LMCustomerRevLicense.csv"  $field_tok$ | dedup "Account Name" | table "Account Name" "Total Active Subscription Revenue _converted"`

Reference: http://docs.splunk.com/Documentation/Splunk/7.1.1/Viz/tokens

View solution in original post

hos_2
Path Finder

Hey Ragate,

Depending on what you set the token value to when creating the drop down you need to add the token into your search like so:

 `source="LMCustomerRevLicense.csv"  $field_tok$ | dedup "Account Name" | table "Account Name" "Total Active Subscription Revenue _converted"`

Reference: http://docs.splunk.com/Documentation/Splunk/7.1.1/Viz/tokens

Ragate
Explorer

Thank You!

0 Karma

Moreilly97
Path Finder

Dont forget to mark this as the answer

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...