Splunk Search

Search key with variable

hello_world15
Engager

I have events like this: Desc_1=eth1
Desc_50=vlan.10
Desc_123=vlan.20
....

the key is in Descr_* format and I want to have a search and disply as select box like this.


<option value="Desc_1">eth1</option>
<option value="Desc_50">vlan.10</option>
<option value="Desc_123">vlan.20</option>

I have some try but no luck because the key is not static... Thanks alot.

Tags (2)
0 Karma

Ayn
Legend

This section of the docs covers this pretty well. http://docs.splunk.com/Documentation/Splunk/latest/Developer/AddDropDowns

0 Karma

Ayn
Legend

Have a look at the fieldForValue and fieldForLabel parameters. One is used for setting the label, and one for setting the value.

0 Karma

hello_world15
Engager

Sorry, may be I have not described my question clearly.

Acutally I need to have a search result like this, so that I will make it become select box.

key value
Desc_1 eth1
Desc_50 vlan.10
Desc_123 vlan.20

Since the key is in Desc_* format, i tried the search like this not work:

Desc_* | stats count by Descr_*

Thanks a lot.

0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...