Splunk Search

How to use conditional tokens to run an append command

julmarqu
Engager

I am creating a table by appending the result of many searches together so each result appears in one row of the table. I would like to use a dropdown to have a row appear or not in the table. Is there a way to do this with Splunk? For example, if my dropdown has the default value 0, all rows should be shown. If the dropdown selects DCA (value 123456), then only the search "loadjob $siar_groups_div_dca_sid$ | stats values(Division) as Division, count as Total" should run, without any of the other rows appearing in the table.

<!-- Filter Dropdown box -->
      <input type="dropdown" token="groupSelection" searchWhenChanged="true">
        <label>Group Filter</label>
        <choice value="0">Entire Network</choice>
        <choice value="123456">DCA</choice>
        <selectFirstChoice>true</selectFirstChoice>
      </input>
      <table>
        <search id="siar_summary_search">
          <query>
            |          loadjob $siar_groups_div_dca_sid$ | stats values(Division) as Division, count as Total
            | append [ loadjob $siar_groups_div_dwt_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dco_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_cac_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_def_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dfw_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dgc_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dmw_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dmo_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dnf_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dnt_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dsa_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dsc_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dst_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dts_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_div_dwf_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_hca_psg_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_hca_shs_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_hca_uce_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_osb_cap_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_osb_div_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_rdc_ada_sid$ | stats values(Division) as Division, count as Total ]
            | append [ loadjob $siar_groups_rdc_ast_sid$ | stats values(Division) as Division, count as Total ]
          </query>
          <earliest>@d</earliest>
          <latest>now</latest>
Tags (1)

somesoni2
Revered Legend

Try this for your table search

<table>
         <search id="siar_summary_search">
           <query>

               | gentimes start=-1 | eval jobname=if("$groupSelection"=0, "$siar_groups_div_dca_sid$ $siar_groups_div_dwt_sid$ $siar_groups_div_dco_sid$ $siar_groups_div_cac_sid$ $siar_groups_div_def_sid$ $siar_groups_div_dfw_sid$ $siar_groups_div_dgc_sid$ $siar_groups_div_dmw_sid$ $siar_groups_div_dmo_sid$ $siar_groups_div_dnf_sid$ $siar_groups_div_dnt_sid$ $siar_groups_div_dsa_sid$ $siar_groups_div_dsc_sid$ $siar_groups_div_dst_sid$ $siar_groups_div_dts_sid$ $siar_groups_div_dwf_sid$ $siar_groups_hca_psg_sid$ $siar_groups_hca_shs_sid$ $siar_groups_hca_uce_sid$ $siar_groups_osb_cap_sid$ $siar_groups_osb_div_sid$ $siar_groups_rdc_ada_sid$ $siar_groups_rdc_ast_sid$", "$siar_groups_div_dca_sid$") | table jobname
               | map search=" |  loadjob $jobname$ | stats values(Division) as Division, count as Total" 
           </query>
           <earliest>@d</earliest>
           <latest>now</latest>
0 Karma

nick405060
Motivator

same problem!

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...