Splunk Search

Drop down not working with Metadata query.

sanju005ind
Communicator

This is the View which I created with a form which contains a dropdown to list department names.All the hosts are tagged with the Dept Names eg. ACC,CORP,FIN.There are about 1500 hosts.

<form>
    <label>Log Sources that are reporting</label>


<searchTemplate>| metadata type=hosts   | fields + host, firstTime, lastTime,totalCount   | convert ctime(firstTime)   | convert ctime(lastTime)  | sort - host | TAGS | search tag::host=$bussiness$ </searchTemplate>
   <earliestTime>-7d</earliestTime>

    <fieldset>
        <input type="dropdown" token="bussiness">
            <label>Select Business</label>
            <choice value="CORP">Corporate</choice>
      <choice value="ACC">Accounts</choice>
      <choice value="Fin">Finance</choice>
        </input>
    </fieldset>

    <row>
        <!-- output the results as a 50 row events table -->
        <table>

            <title>Matching events</title>
            <option name="count">50</option>
        </table>
    </row>
</form>

After I submit the form after selecting CORP from the dropdown option I do not get any results.However when I click on the view results button I see that the query has "None" inserted in it.

| metadata type=hosts   | fields + host, firstTime, lastTime,totalCount   | convert ctime(firstTime)   | convert ctime(lastTime)  | sort - host | TAGS None | search tag::host=CORP

Could you someone help me out with this one as this is urgent?

Tags (2)
0 Karma
1 Solution

thall79
Communicator

In your search | sort - host | TAGS | search tag::host=$bussiness$ have you tried adding the word host to TAGS?

| sort - host | tags host | search tag::host=$bussiness$

Travis.

View solution in original post

thall79
Communicator

In your search | sort - host | TAGS | search tag::host=$bussiness$ have you tried adding the word host to TAGS?

| sort - host | tags host | search tag::host=$bussiness$

Travis.

sanju005ind
Communicator

Thanks.That worked.

0 Karma
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...