@jadengoho ,
You can add a event based token on the completion of search of table by using done
.
E.g.
<dashboard>
<label>Auto Load Of Token</label>
<row>
<panel>
<table>
<search>
<query>| makeresults | eval value=1</query>
<earliest>-1s@s</earliest>
<latest>now</latest>
<done>
<set token="value_token">$result.value$</set>
</done>
</search>
<option name="drilldown">none</option>
</table>
</panel>
</row>
<row>
<panel>
<single>
<search>
<query>|makeresults|eval mytoken=$value_token$</query>
<earliest>-1s@s</earliest>
<latest>now</latest>
</search>
<option name="drilldown">none</option>
</single>
</panel>
</row>
</dashboard>
@jadengoho ,
You can add a event based token on the completion of search of table by using done
.
E.g.
<dashboard>
<label>Auto Load Of Token</label>
<row>
<panel>
<table>
<search>
<query>| makeresults | eval value=1</query>
<earliest>-1s@s</earliest>
<latest>now</latest>
<done>
<set token="value_token">$result.value$</set>
</done>
</search>
<option name="drilldown">none</option>
</table>
</panel>
</row>
<row>
<panel>
<single>
<search>
<query>|makeresults|eval mytoken=$value_token$</query>
<earliest>-1s@s</earliest>
<latest>now</latest>
</search>
<option name="drilldown">none</option>
</single>
</panel>
</row>
</dashboard>
Please refer to this link: https://answers.splunk.com/answers/683394/how-to-put-query-result-in-token-1.html