I am trying to develop a search to populate a drop-down menu in a dashboard with all unique index names. I have tried using the following
| eventcount summarize=false index=* | dedup index | table index
But Splunk keeps complaining that there are duplicate values. Anybody have any idea on how I can accomplish this?
Thanks
Try this query
| eventcount summarize=false index=* | stats count by index | table index
What are you using for your "Field for value" and "Field for label" settings? Try using "index" for both of these.
Try this query
| eventcount summarize=false index=* | stats count by index | table index
Thanks for the reply sundareshr
Still get the same error.
"Duplicate values causing conflict"
do you have any static values in your dropdown? I just tested this and it worked without error.
I have 1 for ALL = *
This is the Default and Initial Value for the drop down menu. Let me remove this and see what I get.
That was it.
Interesting. So I have All set as default and don't have anything defined in inital value and looks like everything is good.
Thanks Sundareshr!