Splunk Enterprise

How to change token value?

pipipipi
Path Finder

Hi all,
I'm in trouble because the value of the fields tag doesn't change when the dropdown changes.

 

 <input type="dropdown" token="tk_report">
      <label>month</label>
      <fieldForLabel>reporting_month</fieldForLabel>
      <fieldForValue>reporting_month</fieldForValue>
      <search>
        <query>| makeresults 
| eval reporting_month=mvrange(relative_time(now(),"- 5mon@mon"),now(),"1mon") 
| table reporting_month 
| mvexpand reporting_month 
| eval reporting_month=strftime(reporting_month,"%Y-%m") 
| sort - reporting_month</query>
        <earliest>@d</earliest>
        <latest>now</latest>
      </search>
      <change>
          <eval token="reporting_month1">strftime(relative_time(strptime($value$."-01","%Y-%m-%d"),"-1mon"),"%Y-%m")</eval>
          <eval token="reporting_month2">strftime(relative_time(strptime($value$."-01","%Y-%m-%d"),"-2mon"),"%Y-%m")</eval>
      </change>
      <selectFirstChoice>true</selectFirstChoice>
    </input>

 

This is table option

 

        <option name="count">10</option>
        <option name="drilldown">row</option>
        <option name="refresh.display">progressbar</option>
        <fields["$reporting_month2$","$reporting_month1$","$tk_report$"]</fields>

 

 I think the first token remains.
but I have no idea to solve this problem.

Is there anyone know how to solve this problem?
Thank you for helping.

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...