Splunk Search

Text box search

ssingh313
Path Finder

Hi this is a follow-up question from my previous question. I was able to create a table with specific Id's being displayed on the table. I am now trying to add a search text box that can be used to display information based on specific ConnId's. I was hoping to
create something where a person can view all the connID logs and then using the search box refine the table to a specific connID search. So even when they don't search for a specific connID they are still able to view the table. Any ideas on how I will be able to do this?

0 Karma
1 Solution

sundareshr
Legend

Try this (replace the query in the panel with your query, just include the token in your base search)

<form>
  <label>Test Dashboard</label>
  <fieldset submitButton="false" autoRun="true">
    <input type="text" token="tok_connID" searchWhenChanged="true">
      <label>connID</label>
    </input>
  </fieldset>
  <row>
    <panel depends="$tok_connID$">
      <event>
        <title></title>
        <search>
          <query>index=_internal $tok_connID$ | head 1</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
      </event>
    </panel>
  </row>
</form>

View solution in original post

sundareshr
Legend

Try this (replace the query in the panel with your query, just include the token in your base search)

<form>
  <label>Test Dashboard</label>
  <fieldset submitButton="false" autoRun="true">
    <input type="text" token="tok_connID" searchWhenChanged="true">
      <label>connID</label>
    </input>
  </fieldset>
  <row>
    <panel depends="$tok_connID$">
      <event>
        <title></title>
        <search>
          <query>index=_internal $tok_connID$ | head 1</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
      </event>
    </panel>
  </row>
</form>
Get Updates on the Splunk Community!

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...