Splunk Search

passing simple search result as token to chart searchstring without any input in a form using simple xml


I have a search query which results the top 1 value from a field called "eventtype" and this top 1 value will change time to time since my dashboard is refreshing for every 1 minute.Now I want to pass this top 1 value as a token to my chart searchstring.means I want to run a search automatically when form is loading and passing the searchresult as token Can we do this one using simple xml.

0 Karma

Splunk Employee
Splunk Employee

recommendation : use a single search with postprocess to populate your top1 table, and the chart.

0 Karma
Get Updates on the Splunk Community!

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...