Splunk Enterprise

How can I write in summary index from dashboard input on change?

spisiakmi
Contributor

Hi, can anybody help, please?

Problem:

In dashboard I have label. If I write something in the label <number> and press Enter, I would like to make an action: write something in summary index.

Label: serial_num
Index: index_sum

Fields to be saved in summary index: $Label$, <actual_time>, identifier

Labels (1)
0 Karma
1 Solution

spisiakmi
Contributor

Hi richgalloway,

thank you for response, I solved this problem. In fact you were absolutely right. I sent the value through a token to search of any element, can be also hidden, and this search ends like | collect index=machinedata_w48_sum testmode=false

 

View solution in original post

spisiakmi
Contributor

Hi richgalloway,

thank you for response, I solved this problem. In fact you were absolutely right. I sent the value through a token to search of any element, can be also hidden, and this search ends like | collect index=machinedata_w48_sum testmode=false

 

richgalloway
SplunkTrust
SplunkTrust

<input> elements cannot write to lookup files.  That only can be done within a <search> element.

What problem are you trying to solve?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...