I have a field extracted called "IP" , I want to display the values of IP in a dropdown . But I want to do it based on the host selected in the first dropdown .How can I do this ?
take a look at my answer here:
https://answers.splunk.com/answers/527016/how-to-create-a-dependent-dropdown-and-multivalue.html
i think it can help overcome your challenge
hope it helps
Hi,
Edit your Host dropdown to add a token in token options
, edit then the IP dropdown, in the Dynamic options, Add your query in Search String:
index="foo" host=$host_tok|s$ | stats count by "IP"
What is your search for the IP drop down? You just use the host filter using the token from host drop down in your IP search.
This is the query I am using for IP drop down.
index=$index1$ host=$hostname$|dedup ip
Looks like you are going in right direction. Is it not working?
Yes , I am not seeing any values in dropdown for IP