Splunk Search

passing simple search result as token to chart searchstring without any input in a form using simple xml


I have a search query which results the top 1 value from a field called "eventtype" and this top 1 value will change time to time since my dashboard is refreshing for every 1 minute.Now I want to pass this top 1 value as a token to my chart searchstring.means I want to run a search automatically when form is loading and passing the searchresult as token Can we do this one using simple xml.

0 Karma

Splunk Employee
Splunk Employee

recommendation : use a single search with postprocess to populate your top1 table, and the chart.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...