Splunk Search

Search key with variable

hello_world15
Engager

I have events like this: Desc_1=eth1
Desc_50=vlan.10
Desc_123=vlan.20
....

the key is in Descr_* format and I want to have a search and disply as select box like this.


<option value="Desc_1">eth1</option>
<option value="Desc_50">vlan.10</option>
<option value="Desc_123">vlan.20</option>

I have some try but no luck because the key is not static... Thanks alot.

Tags (2)
0 Karma

Ayn
Legend

This section of the docs covers this pretty well. http://docs.splunk.com/Documentation/Splunk/latest/Developer/AddDropDowns

0 Karma

Ayn
Legend

Have a look at the fieldForValue and fieldForLabel parameters. One is used for setting the label, and one for setting the value.

0 Karma

hello_world15
Engager

Sorry, may be I have not described my question clearly.

Acutally I need to have a search result like this, so that I will make it become select box.

key value
Desc_1 eth1
Desc_50 vlan.10
Desc_123 vlan.20

Since the key is in Desc_* format, i tried the search like this not work:

Desc_* | stats count by Descr_*

Thanks a lot.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...