Splunk Search

Drop down not working with Metadata query.

sanju005ind
Communicator

This is the View which I created with a form which contains a dropdown to list department names.All the hosts are tagged with the Dept Names eg. ACC,CORP,FIN.There are about 1500 hosts.

<form>
    <label>Log Sources that are reporting</label>


<searchTemplate>| metadata type=hosts   | fields + host, firstTime, lastTime,totalCount   | convert ctime(firstTime)   | convert ctime(lastTime)  | sort - host | TAGS | search tag::host=$bussiness$ </searchTemplate>
   <earliestTime>-7d</earliestTime>

    <fieldset>
        <input type="dropdown" token="bussiness">
            <label>Select Business</label>
            <choice value="CORP">Corporate</choice>
      <choice value="ACC">Accounts</choice>
      <choice value="Fin">Finance</choice>
        </input>
    </fieldset>

    <row>
        <!-- output the results as a 50 row events table -->
        <table>

            <title>Matching events</title>
            <option name="count">50</option>
        </table>
    </row>
</form>

After I submit the form after selecting CORP from the dropdown option I do not get any results.However when I click on the view results button I see that the query has "None" inserted in it.

| metadata type=hosts   | fields + host, firstTime, lastTime,totalCount   | convert ctime(firstTime)   | convert ctime(lastTime)  | sort - host | TAGS None | search tag::host=CORP

Could you someone help me out with this one as this is urgent?

Tags (2)
0 Karma
1 Solution

thall79
Communicator

In your search | sort - host | TAGS | search tag::host=$bussiness$ have you tried adding the word host to TAGS?

| sort - host | tags host | search tag::host=$bussiness$

Travis.

View solution in original post

thall79
Communicator

In your search | sort - host | TAGS | search tag::host=$bussiness$ have you tried adding the word host to TAGS?

| sort - host | tags host | search tag::host=$bussiness$

Travis.

sanju005ind
Communicator

Thanks.That worked.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...