Hey,
I have something like this for a drop-down in a Splunk dashboard:
<input type="dropdown" token="trouID" searchWhenChanged="true">
<label>AssetID</label>
<label>AssetID</label>
<choice value="">All</choice>
<choice value="1243bd9c9206">Aeroplane</choice>
<choice value="4b10fbec">tractor</choice>
<choice value="6cf817f5d">car</choice>
<choice value="14a4f0">skate App</choice>
and every time a new value appears from a search, I have to manually add it. Is there a way in which new values can be added dynamically to the drop-down?
example of search:
index=host....... |stats values (trouID)
thanks
Try this
<input type="dropdown" token="trouID" searchWhenChanged="true">
<label>AssetID</label>
<choice value="*">All</choice>
<search>
<query>
index=host....... |stats count by trouID | table trouID
</query>
<earliest>-7d@h</earliest>
<latest>now</latest>
</search>
<fieldForLabel>trouID</fieldForLabel>
<fieldForValue>trouID</fieldForValue>
<default>*</default>
</input>
You can use a search to define the choices for a dropdown. See here for the how