Hi,
I'm relatively new to Splunk so it's been a bit of a learning curve!
I'm building a dashboard using Splunk Cloud Dashboard Studio that shows both overview and site specific visualisations - key items being a map to show where all sites are, and once a site is selected some specific data.
Basics of Dashboard:
Site Name Dropdown (sets token $SiteName$): All (*)
Site 1
Site 2
Map - configured with markers (lat/long)
Single Value - configured to display the site name that was selected from dropdown ($SiteName$ token)
Basic Search - <base search> | search "Site Name" = "$SiteName$"
Behaviour:
Map and Single Value visualisations work as desired when a specific site is selected.
<base search> | search "Site Name" = "Site 2"
Issue:
When All is selected (sets token $SiteName$ to *) the search becomes:
<base search> | search "Site Name" ="*"
Map - shows all sites (desired)
Single Value - shows 'Site 1' as it's the first returned value of the search (all sites are returned in the search results)
Any Suggestions?
... View more