Hi,
I'm trying to pass the aggregate function from the dropdown menu in the Splunk dashboard to the time-series chart.
for example from dropdown, I want to pass
actual,
Avg(),
max()
to below search
index = _internal sourcetype = * | search field=* Exhost=* | chart max(value) by _time,Exhost
Just create a dropdown with a token name, let's say, "argfunc". Then in your search do
index = _internal sourcetype = * | search field=* Exhost=* | chart $argfunc$(value) by _time,Exhost
As simple as that.