I have a search which will return me field email id.
index=snow description=*CPU* |table number sys_created_by number sys_created_by 1234 firstname.lastname@example.org
Now i want to use
sys_created_by field as the token to populate my dashboard
How to do this?
index=snow description=*CPU* |where sys_created_by=$token$
Thanks but how do I set the token to syscreatedby field first.
As after setting the token only I can use it like $token$
You can use the search event handler to dynamically set a token based on the result. Note that the search event handler only tokenizes the first result, which looks like it should work for you.
Here's what it would look like:
<dashboard> <label>Test Token</label> <search> <query>index=snow description=CPU | table number sys_created_by</query> <earliest>-60m@m</earliest> <latest>now</latest> <done> <set token="sys_created_by">$result.sys_created_by$</set> </done> </search> <row> <panel> <table> <search> <query>index=snow description=CPU sys_created_by=$sys_created_by$</query> <earliest>-60m@m</earliest> <latest>now</latest> </search> </table> </panel> </row> </dashboard>