Splunk Search

Inputlookup - dropdown and multiselect behave weird

light_of_sirius
Explorer

I use an inputlookup to fill a multiselect/dropdown-input.

 

|inputlookup

Errornumber
12
44
68

 

 If i now use a multiselect with token "input_error_number", with "field for value" is "Errornumber",

then the multiselect properly fills the token, so 

 

$input_error_number$ = 12

 

for example.

If i replace the multiselect by a dropdown, then it fills the token with

 

$input_error_number$ = 1 OR 2

 

 This is not desired. Does somebody know how to fix it?

Thx 🙂

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...