Splunk Enterprise

Dynamically load a dropdown from a value chosen from another

fabrizioalleva
Path Finder

Hi all,

I'm trying to populate a dropdown with dynamic values according the value coming from another dropdown, like unit measure for example:

if the dropdown A contains Fruits the B will contain (1000 gr, 100 hg, 1 kG ) instead if the A cointains Liquid B will cointains (1000 ml. 100 cl. )

where 1000/100/1 will be Field For Value

and gr hg and KG will be field for Label.

 

I'm trying something like this :

| makeresults
| eval type="fruits"
| eval unit=case(type=="fruits","1000 gr, 100 hg, 1 kg", type=="liquid","1000 ml, 100 cl", 1=1, "no vlaue")
| rex field=unit "(?<A>.*)\,(?<B>.*)"
| fields A B

But I'm not be able to parameterize the two or three values in the fields to make the split..

Thanks

 

Labels (1)
0 Karma
1 Solution

renjith_nair
Legend

Does this work for you?

| makeresults
| eval type="fruits"
| eval unit=case(type=="fruits","1000#gr, 100#hg, 1#kg", type=="liquid","1000#ml, 100#cl", 1=1, "no vlaue")|makemv unit delim=","|mvexpand unit
| rex field=unit "(?<A>.*)#(?<B>.*)"
| fields A B
---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

Does this work for you?

| makeresults
| eval type="fruits"
| eval unit=case(type=="fruits","1000#gr, 100#hg, 1#kg", type=="liquid","1000#ml, 100#cl", 1=1, "no vlaue")|makemv unit delim=","|mvexpand unit
| rex field=unit "(?<A>.*)#(?<B>.*)"
| fields A B
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

fabrizioalleva
Path Finder

Thanks a lot

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...