I'm creating a splunk dashboard and part of what I would like to do is create a drop down that is populated using a search query. I've confirmed that my search query returns results for the time frame I want and I've confirmed that some of the results contain the field that I want to use for label and value. But for some reason my dropdown is disabled and has no data in it. Am I correct to assume that if the search query is returning results and at least some of those results contain the field that I want to use in my dropdown that my dropdown should populate and be usable? Can anyone give me any suggestions as to why my dropdown isn't working? Note: I deliberately left out my search string and the field i'm using because I assumed my description above would be enough. Please let me know if it would be helpful to include these values
... View more