Splunk Search

Text box search

ssingh313
Path Finder

Hi this is a follow-up question from my previous question. I was able to create a table with specific Id's being displayed on the table. I am now trying to add a search text box that can be used to display information based on specific ConnId's. I was hoping to
create something where a person can view all the connID logs and then using the search box refine the table to a specific connID search. So even when they don't search for a specific connID they are still able to view the table. Any ideas on how I will be able to do this?

0 Karma
1 Solution

sundareshr
Legend

Try this (replace the query in the panel with your query, just include the token in your base search)

<form>
  <label>Test Dashboard</label>
  <fieldset submitButton="false" autoRun="true">
    <input type="text" token="tok_connID" searchWhenChanged="true">
      <label>connID</label>
    </input>
  </fieldset>
  <row>
    <panel depends="$tok_connID$">
      <event>
        <title></title>
        <search>
          <query>index=_internal $tok_connID$ | head 1</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
      </event>
    </panel>
  </row>
</form>

View solution in original post

sundareshr
Legend

Try this (replace the query in the panel with your query, just include the token in your base search)

<form>
  <label>Test Dashboard</label>
  <fieldset submitButton="false" autoRun="true">
    <input type="text" token="tok_connID" searchWhenChanged="true">
      <label>connID</label>
    </input>
  </fieldset>
  <row>
    <panel depends="$tok_connID$">
      <event>
        <title></title>
        <search>
          <query>index=_internal $tok_connID$ | head 1</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
      </event>
    </panel>
  </row>
</form>
Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...

Enterprise Security Content Update (ESCU) | New Releases

In March, the Splunk Threat Research Team had 2 releases of security content via the Enterprise Security ...

Join the Splunk Developer Program Hackathon: Splunk Build-a-thon!

The Splunk Developer Program is launching in beta, and we’re celebrating with an exciting hackathon! This is ...