Splunk Enterprise

How could I show the value in my data in the drop down?

Questioner
Path Finder

I want to show the drop down value automatically about data name "landing_time".

So I wrote my code like this.

| eval st_time= round(landing_time,0)
| where st_time<=90
| stats values by st_time
| sort st_time

 But it show all landing_time less than 90, not fil the landing_time. For example..

lading_time : 7, 15, 17, 24, 30..
drop down data show : 0, 1, 2, 3, 4, .......17, 18, 19,....30, 31...

 How could I show only landing_time in the drop down?

Tags (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Change you fieldForLabel and fieldForValue attributes

   <fieldForLabel>st_time</fieldForLabel>
   <fieldForValue>st_time</fieldForValue>

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please share your dashboard source code in a code block

0 Karma

Questioner
Path Finder

This is my code about the drop down

<input type="dropdown" token="start_time" searchWhenChanged="true">
<label>First IR init Time (sec)</label>
<fieldForLabel>start_time</fieldForLabel>
<fieldForValue>start_time</fieldForValue>
<search>
<query>index=idx_ptd_dataset sourcetype="type:ptd_dataset:data" corp="flight"
| where !isnull(location)
| where !isnull(landing_time)
| eval st_time= round(landing_time,0)
| where st_time &lt;=90
| stats values by st_time
| sort st_time</query>
</search>
<default>ALL</default>
<choice value="ALL">ALL</choice>
</input>

 

 



 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Change you fieldForLabel and fieldForValue attributes

   <fieldForLabel>st_time</fieldForLabel>
   <fieldForValue>st_time</fieldForValue>
0 Karma

Questioner
Path Finder

Thank you for you help!
It work!!

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...