Splunk Search

Condition value NOT equal to....whatever



I have this XML code. What I'm trying to do is when the value = *, run a separate query and when the value is anything else but * run a different query. I'm having difficulty figuring out how to configure condition value to be not equal to *

 <input type="dropdown" token="mso_selection" searchWhenChanged="true">
      <label>Select a MSO</label>
        <query>index=wholesale_app  sourcetype=wholesale_mobile_app buildTarget | dedup buildTarget</query>
      <choice value="*">- All -</choice>

         <condition value="*">
           <set token="tokSearchQueryPanel1">index=mso_statistics sourcetype=ic_connectivity_5min-too_small  stat_name=subscribers |rex "\d+\s(?<mso>\w+)"|stats max(stat_val) as Subscribers by mso|stats sum(Subscribers) as count</set>
           <unset token="tokSearchQueryPanel2"></unset>

         <condition value"*">     (this line is what I'm trying to figure out)

           <set token="tokSearchQueryPanel2">index=mso_statistics sourcetype=ic_connectivity_5min-too_small  stat_name=subscribers |rex "\d+\s(?&lt;mso&gt;\w+)"|stats max(stat_val) as Subscribers by mso|where like(mso,"%$mso_selection$%") |stats sum(Subscribers) as count</set>
           <unset token="tokSearchQueryPanel1"></unset>

1 Solution


@dbcase, you can just use a condition block without any match expression. This servers as else condition.

      <condition value="*">
             <-- Your Code For Value Matching Asterix -->
             <--  Your Code For All Other Values not matching Asterix -->

Refer to one of my comments in my previous answer on similar question: https://answers.splunk.com/answers/596673/how-can-i-get-the-value-of-a-token-as-a-search-eva.html

| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

Esteemed Legend

Condition on label="All" instead.

0 Karma


@dbcase, you can just use a condition block without any match expression. This servers as else condition.

      <condition value="*">
             <-- Your Code For Value Matching Asterix -->
             <--  Your Code For All Other Values not matching Asterix -->

Refer to one of my comments in my previous answer on similar question: https://answers.splunk.com/answers/596673/how-can-i-get-the-value-of-a-token-as-a-search-eva.html

| makeresults | eval message= "Happy Splunking!!!"
Get Updates on the Splunk Community!

Splunk Platform | Upgrading your Splunk Deployment to Python 3.9

Splunk initially announced the removal of Python 2 during the release of Splunk Enterprise 8.0.0, aiming to ...

From Product Design to User Insights: Boosting App Developer Identity on Splunkbase

co-authored by Yiyun Zhu & Dan Hosaka Engaging with the Community at .conf24 At .conf24, we revitalized the ...

Detect and Resolve Issues in a Kubernetes Environment

We’ve gone through common problems one can encounter in a Kubernetes environment, their impacts, and the ...