Splunk Search

How to set up radio button or checkbox to alter text search?

raborder
New Member

I'd like to use a radio button or checkbox to alter a search
i.e. toggle between either

Index=$index$ host=$host$ source=$source$

or

Index=$index$ host=$host$ source=$source$ **NOT INFO**

I cannot find a simple way to do this, I find radio buttons will not uncheck, and leaving an option blank gets me an undefined search etc.

Is there a way to do this?

Tags (4)
0 Karma
1 Solution

renjith_nair
Legend

@raborder,

Try this example with radio button
- First option searches internal index for all log levels including INFO
- Second option searches internal index for all log levels excluding INFO

<form>
  <label>Search Switch</label>
  <fieldset submitButton="false">
    <input type="radio" token="search_tok">
      <label>Select the search</label>
      <choice value="">Include INFO</choice>
      <choice value="NOT &quot;INFO&quot;">Exclude INFO</choice>
      <default></default>
    </input>
  </fieldset>
  <row>
    <panel>
      <table>
        <search>
          <query>index=_* $search_tok$|stats count by log_level</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </table>
    </panel>
  </row>
</form>
---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

@raborder,

Try this example with radio button
- First option searches internal index for all log levels including INFO
- Second option searches internal index for all log levels excluding INFO

<form>
  <label>Search Switch</label>
  <fieldset submitButton="false">
    <input type="radio" token="search_tok">
      <label>Select the search</label>
      <choice value="">Include INFO</choice>
      <choice value="NOT &quot;INFO&quot;">Exclude INFO</choice>
      <default></default>
    </input>
  </fieldset>
  <row>
    <panel>
      <table>
        <search>
          <query>index=_* $search_tok$|stats count by log_level</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </table>
    </panel>
  </row>
</form>
---
What goes around comes around. If it helps, hit it with Karma 🙂

raborder
New Member

Awesome Renjith. This works as I want. I'll go over it and work out why my solution didn't 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...