Splunk Search

How to use conditional tokens to run an append command

julmarqu
Engager

I am creating a table by appending the result of many searches together so each result appears in one row of the table. I would like to use a dropdown to have a row appear or not in the table. Is there a way to do this with Splunk? For example, if my dropdown has the default value 0, all rows should be shown. If the dropdown selects DCA (value 123456), then only the search "loadjob $siar_groups_div_dca_sid$ | stats values(Division) as Division, count as Total" should run, without any of the other rows appearing in the table.

<!-- Filter Dropdown box -->
      <input type="dropdown" token="groupSelection" searchWhenChanged="true">
        <label>Group Filter</label>
        <choice value="0">Entire Network</choice>
        <choice value="123456">DCA</choice>
        <selectFirstChoice>true</selectFirstChoice>
      </input>
      <table>
        <search id="siar_summary_search">
          <query>
            |          loadjob $siar_groups_div_dca_sid$ | stats values(Division) as Division, count as Total
            | append [ loadjob $siar_groups_div_dwt_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dco_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_cac_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_def_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dfw_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dgc_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dmw_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dmo_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dnf_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dnt_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dsa_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dsc_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dst_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dts_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dwf_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_hca_psg_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_hca_shs_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_hca_uce_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_osb_cap_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_osb_div_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_rdc_ada_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_rdc_ast_sid$ | stats values(Division) as Division, count as Total ]
          </query>
          <earliest>@d</earliest>
          <latest>now</latest>
Tags (1)

somesoni2
Revered Legend

Try this for your table search

<table>
         <search id="siar_summary_search">
           <query>

               | gentimes start=-1 | eval jobname=if("$groupSelection"=0, "$siar_groups_div_dca_sid$ $siar_groups_div_dwt_sid$ $siar_groups_div_dco_sid$ $siar_groups_div_cac_sid$ $siar_groups_div_def_sid$ $siar_groups_div_dfw_sid$ $siar_groups_div_dgc_sid$ $siar_groups_div_dmw_sid$ $siar_groups_div_dmo_sid$ $siar_groups_div_dnf_sid$ $siar_groups_div_dnt_sid$ $siar_groups_div_dsa_sid$ $siar_groups_div_dsc_sid$ $siar_groups_div_dst_sid$ $siar_groups_div_dts_sid$ $siar_groups_div_dwf_sid$ $siar_groups_hca_psg_sid$ $siar_groups_hca_shs_sid$ $siar_groups_hca_uce_sid$ $siar_groups_osb_cap_sid$ $siar_groups_osb_div_sid$ $siar_groups_rdc_ada_sid$ $siar_groups_rdc_ast_sid$", "$siar_groups_div_dca_sid$") | table jobname
               | map search=" |  loadjob $jobname$ | stats values(Division) as Division, count as Total" 
           </query>
           <earliest>@d</earliest>
           <latest>now</latest>
0 Karma

nick405060
Motivator

same problem!

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...