Hello all,
I am relatively new to Splunk and creating dashboard with XML, so any recommendations and tips are greatly appreciated.
So I have a dashboard with a drop-down menu with a list of sources - I did this because we a have a weekly CSV report so the user can pick a file based on its date within the file name. When the panel relying on the "source" token to do the search, it's missing a backslash to work properly. The source code and explanation below.
Drop-down menu:
<input type="dropdown" token="source_csv" searchWhenChanged="true">
<label>Select a report week:</label>
<prefix>source=</prefix>
<default>*</default>
<choice value="*">All</choice>
<fieldForLabel>source</fieldForLabel>
<fieldForValue>source</fieldForValue>
<search>
<query>
index="example_reports" | chart count by source
</query>
</search>
</input>
So when a panel with the search below is done, nothing shows up because it's missing a backslash.
host="example_host" index="example_index" $source_csv$ | stats distinct_count(ip)
The search query comes out as:
host="example_host" index="example_index" source=D:\example\report-2018-12-25.csv | stats distinct_count(ip)
The issue is that the source value needs two backslashes for it to work:
source=D:\example\report-2018-12-25.csv
Is there anyway to get the token to have two backslashes to the directory with the token or search query? Thank you in advance.
I did search for solutions on this by adding |s$ and search string, but couldn't get it to work right...
... View more