Splunk Search

How to use token with a field created with "eval"?

Goldenfit
Explorer

So i am trying to link this to a token from another panel but since "message_id" is a created field, it doesn't work. Is there anyway I can make this work?

 

<index> <host>
| eval message_id=AREA.SUBID
| stats count by USER, TEXT
| search message_id="$messid1$"
| sort - count

 

Labels (2)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Goldenfit ,

after a stats command, you have only the fields in the stats command, in your case: count, USER and TEXT.

So you cannot have message_id for searching after the stats command.

You have to put the search command before the stats or add the message_id field to the stats.

Ciao.

Giuseppe

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's not that message_id is a "created field".

You may need to set a token to $results.message_id$ as part of the <done> element of your query, but you have a bigger problem:  the message_id field doesn't exist.

The stats command transforms the results so the only fields passed to the rest of the query are 'count', 'USER', and 'TEXT'.  There is no message_id field to search for or to use in another panel.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Taruchit
Contributor

Hi @Goldenfit,

Can you please share the code used for defining your token?

Thank you 

0 Karma

Goldenfit
Explorer

So basically i have another panel 

Goldenfit_0-1684329030742.png

Goldenfit_1-1684329066278.png

my goal is that when I click on one of the message_id displayed in the chart above, my first query in the original post udates it to display TEXT and USER with this particular message_id

 

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...