Dashboards & Visualizations

Dropdown based on another dropdown

sarahw3
Explorer

I have a dropdown menu where you can select a state and I want another dropdown for city. Is there a way that the city dropdown then only has the options for the state chosen? For example, if I chose Massachusetts in the first dropdown, Los Angeles would not be an option to pick on the second drop down menu.

0 Karma
1 Solution

cmerriman
Super Champion

use the token that is creating the state dropdown in your search that is creating the city dropdown.

for instance, if $state$ is the token name for your state dropdown:

  sourcetype="support_csv" location=$state$|stats count by city|fields - count

View solution in original post

0 Karma

sscullion_splun
Splunk Employee
Splunk Employee

What you want is a cascading input.

First input populating search:
sourcetype=mySourcetype | stats count by "State"

First input token: state_token

Second input populating search:
sourcetype=mySourcetype State=$state_token|s$ | stats count by "City"

Note the use of a |s filter with the state_token. This will add quote marks to capture states like North Dakota.

0 Karma

woodcock
Esteemed Legend

Use a populating search for the 2nd dropdown that uses something like |inputcsv YourFileWithStatesAndCities Here | search State=$state$

0 Karma

cmerriman
Super Champion

use the token that is creating the state dropdown in your search that is creating the city dropdown.

for instance, if $state$ is the token name for your state dropdown:

  sourcetype="support_csv" location=$state$|stats count by city|fields - count
0 Karma

sarahw3
Explorer

It is saying my search produces no result. I tried it as State=$state$ and that didn't work either.

0 Karma

sarahw3
Explorer

When I get rid of the part with the token it works but it shows all the cities for all states.

0 Karma

cmerriman
Super Champion

can you paste your xml from your dashboard so i can see what might be happening? i just need the part from <fieldset...> to </fieldset> where all the dropdowns are

0 Karma

sarahw3
Explorer

I got it! I just had to put the token in quotes! Thank you so much for all your help! You are a life saver!! I wish I had all your splunk knowledge hahaha!

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...