Splunk Search

Inputlookup - dropdown and multiselect behave weird

I use an inputlookup to fill a multiselect/dropdown-input.





 If i now use a multiselect with token "input_error_number", with "field for value" is "Errornumber",

then the multiselect properly fills the token, so 


$input_error_number$ = 12


for example.

If i replace the multiselect by a dropdown, then it fills the token with


$input_error_number$ = 1 OR 2


 This is not desired. Does somebody know how to fix it?

Thx 🙂

Labels (2)
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!