Splunk Search

Search key with variable

hello_world15
Engager

I have events like this: Desc_1=eth1
Desc_50=vlan.10
Desc_123=vlan.20
....

the key is in Descr_* format and I want to have a search and disply as select box like this.


<option value="Desc_1">eth1</option>
<option value="Desc_50">vlan.10</option>
<option value="Desc_123">vlan.20</option>

I have some try but no luck because the key is not static... Thanks alot.

Tags (2)
0 Karma

Ayn
Legend

This section of the docs covers this pretty well. http://docs.splunk.com/Documentation/Splunk/latest/Developer/AddDropDowns

0 Karma

Ayn
Legend

Have a look at the fieldForValue and fieldForLabel parameters. One is used for setting the label, and one for setting the value.

0 Karma

hello_world15
Engager

Sorry, may be I have not described my question clearly.

Acutally I need to have a search result like this, so that I will make it become select box.

key value
Desc_1 eth1
Desc_50 vlan.10
Desc_123 vlan.20

Since the key is in Desc_* format, i tried the search like this not work:

Desc_* | stats count by Descr_*

Thanks a lot.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...