Splunk Dev

Why is dropdown not working with basesearch?



I have created a base search, and have an event table to display the results. Problem is, only the 'All' value is working correctly. When i select other options, nothing is being display. The dropdown is showing me the correct options.  Below is my codes, i have changed some of the words, as i can't use the actual data here.


This is my base search, i have set it up at the top



<form theme="dark">
  <search id="baseSearch">
    <query>source="ErrorLog" ESPACE_NAME IN (Customer, Vendors, Friends) | replace "Customer" WITH "Customer Name", "Vendors" with "Vendors Name", "Friends" WITH "Friends Name" IN ESPACE_NAME</query>
  <fieldset submitButton="false" autoRun="true">
    <input type="time" token="field1">




 This is the codes for my dropdown



      <title>Error Log</title>
      <input type="dropdown" token="ProfileLog" searchWhenChanged="true">
        <search base="baseSearch">
          <query>| stats count by ESPACE_NAME</query>
        <choice value="*">All</choice>
        <search base="baseSearch">
          <query>| search ESPACE_NAME=$ProfileLog$</query>
        <option name="list.drilldown">none</option>
        <option name="refresh.display">progressbar</option>




Any assistance is appreciated!! Thank you

Labels (1)
Tags (2)
0 Karma
1 Solution


Hi @junmun-chan,

Since your token values contains spaces you have use tokens between double-quotes like below;

      <title>Error Log</title>
      <input type="dropdown" token="ProfileLog" searchWhenChanged="true">
        <search base="baseSearch">
          <query>| stats count by ESPACE_NAME</query>
        <choice value="*">All</choice>
        <search base="baseSearch">
          <query>| search ESPACE_NAME="$ProfileLog$"</query>
        <option name="list.drilldown">none</option>
        <option name="refresh.display">progressbar</option>
If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

0 Karma


Hi @junmun-chan,

Since your token values contains spaces you have use tokens between double-quotes like below;

      <title>Error Log</title>
      <input type="dropdown" token="ProfileLog" searchWhenChanged="true">
        <search base="baseSearch">
          <query>| stats count by ESPACE_NAME</query>
        <choice value="*">All</choice>
        <search base="baseSearch">
          <query>| search ESPACE_NAME="$ProfileLog$"</query>
        <option name="list.drilldown">none</option>
        <option name="refresh.display">progressbar</option>
If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma


Oh yes scelikok, it works now!


Thank you!!

0 Karma
Get Updates on the Splunk Community!

Splunk Platform | Upgrading your Splunk Deployment to Python 3.9

Splunk initially announced the removal of Python 2 during the release of Splunk Enterprise 8.0.0, aiming to ...

From Product Design to User Insights: Boosting App Developer Identity on Splunkbase

co-authored by Yiyun Zhu & Dan Hosaka Engaging with the Community at .conf24 At .conf24, we revitalized the ...

Detect and Resolve Issues in a Kubernetes Environment

We’ve gone through common problems one can encounter in a Kubernetes environment, their impacts, and the ...