Splunk Enterprise

How can I write in summary index from dashboard input on change?

spisiakmi
Communicator

Hi, can anybody help, please?

Problem:

In dashboard I have label. If I write something in the label <number> and press Enter, I would like to make an action: write something in summary index.

Label: serial_num
Index: index_sum

Fields to be saved in summary index: $Label$, <actual_time>, identifier

Labels (1)
0 Karma
1 Solution

spisiakmi
Communicator

Hi richgalloway,

thank you for response, I solved this problem. In fact you were absolutely right. I sent the value through a token to search of any element, can be also hidden, and this search ends like | collect index=machinedata_w48_sum testmode=false

 

View solution in original post

spisiakmi
Communicator

Hi richgalloway,

thank you for response, I solved this problem. In fact you were absolutely right. I sent the value through a token to search of any element, can be also hidden, and this search ends like | collect index=machinedata_w48_sum testmode=false

 

richgalloway
SplunkTrust
SplunkTrust

<input> elements cannot write to lookup files.  That only can be done within a <search> element.

What problem are you trying to solve?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...

Starting With Observability: OpenTelemetry Best Practices

Tech Talk Starting With Observability: OpenTelemetry Best Practices Tuesday, October 17, 2023   |  11AM PST / ...