Splunk Enterprise

help on command as a token

jip31
Motivator

hi

 

I would like to know if it is possible to ruse a comand as a token

I need to replace the command "perc90"  by "perc95" from a dropdown list

| stats perc90(web_dur)

thanks

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
  <fieldset>
    <input type="dropdown" token="aggregator">
      <label>aggregator</label>
      <choice value="sum">sum</choice>
      <choice value="count">count</choice>
      <choice value="perc90">perc90</choice>
      <choice value="perc95">perc95</choice>
      <default>sum</default>
      <initialValue>sum</initialValue>
    </input>
  </fieldset>
  <row>
    <panel>
      <table>
        <search>
          <query>| makeresults count=20 
| eval count=random()%100
| stats $aggregator$(count) as $aggregator$</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
      </table>
    </panel>
  </row>

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
  <fieldset>
    <input type="dropdown" token="aggregator">
      <label>aggregator</label>
      <choice value="sum">sum</choice>
      <choice value="count">count</choice>
      <choice value="perc90">perc90</choice>
      <choice value="perc95">perc95</choice>
      <default>sum</default>
      <initialValue>sum</initialValue>
    </input>
  </fieldset>
  <row>
    <panel>
      <table>
        <search>
          <query>| makeresults count=20 
| eval count=random()%100
| stats $aggregator$(count) as $aggregator$</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
      </table>
    </panel>
  </row>
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...