Splunk Search

Multiselect input

chuck_life09
Path Finder

Hi,

In my dashboard i have set of inputs and when i submit the values gets stored in a lookup file. 

2 dropdowns , 1 multiselect and 1 text field

Can i store the values from the multiselect into separate records in the lookup or how do i expand as all are clustered like this, not sure how to give a separator.

Multiselect  name - Type

AAA ttt

BBB fff

CCC eee hhh qqq

... in the lookup file it shows like - AAA ttt BBB fff CCC eee hhh qqq. how do i separate it?

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @chuck_life09,

did you tried to create a lookup like this:

Name   Type
AAA    ttt
AAA    sss
BBB    fff
BBB    ggg
CCC    eee
CCC    hhh
CCC    qqq

 Calling it in the multivalue?

Ciao.

Giuseppe

0 Karma

chuck_life09
Path Finder

hi @gcusello 

the Multiselect input name is 

Type

1.my name is

2.the desktop is mine

3.there are many likes

Like this it will be, and it will be stored in the lookup as this 

----------------------------

time                              ID                count            Type 

13th april 2021      1234              4                  my name is the desktop is mine there are many likes

---------------------

I am not sure how to split it , can it be stored as this

time                              ID                count            Type 

13th april 2021      1234              4                  my name is 

13th april 2021      1234              4                  the desktop is mine 

13th april 2021      1234              4                  there are many likes

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @chuck_life09,

Sorry but I don't understand your requirement:

  • you have a multiselect,
  • the values of this multiselect are  "my name is" "the desktop is mine" "there are many likes",
  • you want to have these values in a lookup to dinamically manage them,
  • and use them to filter events in dashboard's panels.

What's the problem, to have these values in the lookup? or what else?

As I said, did you tried to put each value in a different row of the lookup, so you can call all the values from the lookup?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...