Splunk Search

Multiple independent dropdowns in a Dashboard

behymejt2012
Path Finder

Creating a dashboard with 3 independent dropdowns (country,state,city). The ideas is for the user to select or more of the dropdowns and based on the selection it will populate a table.

For example, if the user selects only the country dropdown (lets say United States) then the other 2 dropdowns will default to selecting all.

When creating the search for the table and passing the value for the country is simple, my question is for the other two fields, is it possible to do the following or something similar:

| where country ="United States", state=ALL, city=ALL

Any help or guidance would be appreciated!!

Tags (2)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

you can either set the default value to "*", or you can have the input/dropdown use a prefix to the field value. if there is no field value selected at all, then the prefix will also be omitted, so the term will not even exist in your search template.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...