I have a search which will return me field email id.
index=snow description=*CPU* |table number sys_created_by
number sys_created_by
1234 abcd@bcd.com
Now i want to use sys_created_by
field as the token to populate my dashboard
How to do this?
index=snow description=*CPU* |where sys_created_by=$token$
You can use the search event handler to dynamically set a token based on the result. Note that the search event handler only tokenizes the first result, which looks like it should work for you.
Here's what it would look like:
<dashboard>
<label>Test Token</label>
<search>
<query>index=snow description=CPU | table number sys_created_by</query>
<earliest>-60m@m</earliest>
<latest>now</latest>
<done>
<set token="sys_created_by">$result.sys_created_by$</set>
</done>
</search>
<row>
<panel>
<table>
<search>
<query>index=snow description=CPU sys_created_by=$sys_created_by$</query>
<earliest>-60m@m</earliest>
<latest>now</latest>
</search>
</table>
</panel>
</row>
</dashboard>
You can use the search event handler to dynamically set a token based on the result. Note that the search event handler only tokenizes the first result, which looks like it should work for you.
Here's what it would look like:
<dashboard>
<label>Test Token</label>
<search>
<query>index=snow description=CPU | table number sys_created_by</query>
<earliest>-60m@m</earliest>
<latest>now</latest>
<done>
<set token="sys_created_by">$result.sys_created_by$</set>
</done>
</search>
<row>
<panel>
<table>
<search>
<query>index=snow description=CPU sys_created_by=$sys_created_by$</query>
<earliest>-60m@m</earliest>
<latest>now</latest>
</search>
</table>
</panel>
</row>
</dashboard>
You can use the token directly inside the query.
index=snow description=CPU |table number $token$
Thanks but how do I set the token to sys_created_by field first.
As after setting the token only I can use it like $token$
Hi,
Try to check the link below:
http://docs.splunk.com/Documentation/Splunk/6.5.0/Viz/tokens
tks
Rodrigo Ribeiro