Splunk Search

Search key with variable

hello_world15
Engager

I have events like this: Desc_1=eth1
Desc_50=vlan.10
Desc_123=vlan.20
....

the key is in Descr_* format and I want to have a search and disply as select box like this.


<option value="Desc_1">eth1</option>
<option value="Desc_50">vlan.10</option>
<option value="Desc_123">vlan.20</option>

I have some try but no luck because the key is not static... Thanks alot.

Tags (2)
0 Karma

Ayn
Legend

This section of the docs covers this pretty well. http://docs.splunk.com/Documentation/Splunk/latest/Developer/AddDropDowns

0 Karma

Ayn
Legend

Have a look at the fieldForValue and fieldForLabel parameters. One is used for setting the label, and one for setting the value.

0 Karma

hello_world15
Engager

Sorry, may be I have not described my question clearly.

Acutally I need to have a search result like this, so that I will make it become select box.

key value
Desc_1 eth1
Desc_50 vlan.10
Desc_123 vlan.20

Since the key is in Desc_* format, i tried the search like this not work:

Desc_* | stats count by Descr_*

Thanks a lot.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...