Hi @chris7535,
Using the query you posted above after the first table command you no longer have the EventCode fields not the Values or Action field so the other evals will do nothing and the tables as well.
If you want to control the way a dashboard or table is presented based on a token you need to use conditional tokens as shown here :
https://docs.splunk.com/Documentation/Splunk/7.2.6/Viz/tokens
And here :
https://docs.splunk.com/Documentation/Splunk/7.2.6/Viz/ContextualDrilldown#Configure_conditional_behavior
Let me know if that helps.
Cheers,
David
... View more