Splunk Search

Can you do conditionals in searches where the action is to add/change the search string?

j4adam
Communicator

I did a lot of reading last night about eval ifs and read several posts that danced around the edge of being relevant enough to help me.

My situation is this:

I have a dashboard that has a table that's fueled by ~4 search tokens and I wanted to add a check box that would add another column to the table if checked. The original plan was to do (psuedo code):

if (checkbox is checked) append another field to my table command in the search. Else leave as it is.

So far I've been unable to find out if this is possible. I've read a lot of posts about people hiding panels by editing the XML. I'd like a more elegant solution than simply having two separate panels and inverting their visibility with the check box.

0 Karma

sundareshr
Legend

Try this run anywhere sample. You should be able to copy this, paste it in to your search window and see the results

index=_internal | table [| makeresults | eval search="_time sourcetype"." source" | table search]
0 Karma

sundareshr
Legend

See if this works

your base search | table [| makeresults | eval search="field1 field2".$fieldnamefromcheckbox$ | table search]
0 Karma

j4adam
Communicator

That didn't work, but maybe I did it wrong.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...