Recently upgraded to Splunk 6.5.0. I am trying to access the first row from the search result in a dashboard. In version 6.3.2, there was an event handler 'finalized' which provides access to the first row
Documentation from version 6.3.2 : http://docs.splunk.com/Documentation/Splunk/6.3.2/Viz/tokens#Define_search_tokens
But in 6.5.0 there is no 'finalized' handler. Only handlers available are progress, done, cancel, error, fail and none of those provide access to first row of the result
Documentation from version 6.5.0: http://docs.splunk.com/Documentation/Splunk/6.5.0/Viz/tokens#Define_search_tokens
Is there any workaround? Is it done differently in 6.5.0?
I think its a typo in the 6.5 documentation. The
done handler provides access to first row of the result. When I tried to access
result.field-name in the
done handler it worked . I tried eval to set the token which did not work but
set token worked.
I am not sure you understand. @adevi is trying to use the $result.FIELD$ feature that was in 6.3 and 6.4, but seems to be gone in 6.5. This feature allowed one to assign the result from the first row to a token for other uses in the Dashboard.