I am trying to add a dropdown in a Dashboard in Splunk cloud using the index field host from a metric dataset. I want the host field to dynamically update the dropdown from the host field available in the dataset at any one time. I am using the search for the data source of the dropdown as '|mcatalog values(host) where index=em_metrics | mvexpand values(host)'. All other settings on the drop down are the defaults. I have tried changing the search several times and have been unable to get it to work. Any suggestions would be greatly appreciated.
... View more