Splunk Search

Passing token to dashboard query

nagarjuna119
Engager

Passing a token to dashboard using below is not working, dashboard is stuck on "search is waiting for input"

message below is a json field so using spath to parse its fields, I have used the token in the title and it showed the right value, and below query works fine without token 

index="indextest" source="my source" sourcetype="ab-xyz" | spath input=message | UserName = $UserName_Token$
| table JobServiceId CreateDateTime Status UserName 

 

 

0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

There's an error in your SPL. This is not valid SPL, but maybe that's a typo

 

...
| UserName = $UserName_Token$
...

 

Did you mean?

| where UserName = "$UserName_Token$"

Note quotes

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

There's an error in your SPL. This is not valid SPL, but maybe that's a typo

 

...
| UserName = $UserName_Token$
...

 

Did you mean?

| where UserName = "$UserName_Token$"

Note quotes

0 Karma

nagarjuna119
Engager

That worked if I select a specific value thank you.
However when I use  * as default value to return all the entires it does't return any results 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

This is where the use of '| where' or '| search' is relevant.

If using where, then it's a regex, so just having * will not work, it needs to be .* but if you use search you can just use * as the wildcard, but it's less precise as using where.

 

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...