Splunk Search

Need Help on Drop down

mahesh27
Communicator

Created 2 drop downs in a dashboard. 

1. Country

2. Applications (getting data from .csv file)

In applications drop down i am seeing individual applications in the drop down but I need "All" options in the dropdown. How can i do it??

 

<input type="radio" token="country">
<label>Country</label>
<choice value="india">India</choice>
<choice value="australian">Australian</choice>
<default>india</default>
<intialValue>india</intialValue>
<change>
<condition label="India">
<set token="sorc">callsource</set>
</condition>
<condition label="Australian">
<set token="sorc">callsource2</set>
</condition>
</change>
</input>
<input type="dropdown" token="application" searchWhenChanged="false">
<label>Application</label>
<fieldForLabel>application_Succ</fieldForLabel>
<fieldForValue>application_Fail</fieldForValue>
<search>
<query> |inputlookup application_lists.csv
|search country=$country$
|sort country application_Succ
|fields application_Succ application_Fail</query>
<earliest>-15m</earliest>
<latest>now</latest>
</search>
</input>
</fieldset>

 

 

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
<input type="dropdown" token="application" searchWhenChanged="false">
<label>Application</label>
<choice value="*">All</choice>
<fieldForLabel>application_Succ</fieldForLabel>
<fieldForValue>application_Fail</fieldForValue>
<search>
<query> |inputlookup application_lists.csv
|search country=$country$
|sort country application_Succ
|fields application_Succ application_Fail</query>
<earliest>-15m</earliest>
<latest>now</latest>
</search>
</input>

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Add the all choice to the input - you can have both fixed and dynamic choices in the same dropdown

mahesh27
Communicator

Where I should add that, near application drop down??

can u pls share me the code????

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
<input type="dropdown" token="application" searchWhenChanged="false">
<label>Application</label>
<choice value="*">All</choice>
<fieldForLabel>application_Succ</fieldForLabel>
<fieldForValue>application_Fail</fieldForValue>
<search>
<query> |inputlookup application_lists.csv
|search country=$country$
|sort country application_Succ
|fields application_Succ application_Fail</query>
<earliest>-15m</earliest>
<latest>now</latest>
</search>
</input>

mahesh27
Communicator

It was so simple, Thank you so much

it worked

😊

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...