Dashboards & Visualizations

How to achieve cascading dynamic drop downs with CSV data?

ramana4u
Loves-to-Learn

Dear Community,

How do I display values from second dropdown values based on first dropdown value.

 

<input type="dropdown" token="site" searchWhenChanged="true">

| inputlookup regions_instances.csv | fields region region_value

 

<input type="dropdown" token="instance" searchWhenChanged="true">

| inputlookup regions_instances.csv | search region=$site$ | fields  instance instance_value

 

 

Labels (1)
Tags (1)
0 Karma

gcusello
Legend

Hi @ramana4u,

the approach you followed is correct, what's your issue or doubt?

Ciao.

Giuseppe

0 Karma

ramana4u
Loves-to-Learn

Image1.PNG

 

Thanks for looking into this.

First dropdown is ok.   No values shown in the second dropdown.

 

0 Karma

gcusello
Legend

Hi @ramana4u,

you should check if the fields in the second lookup is the same of the first and that the value from the first is present in teh second.

Then you don't need to use where, you could use where in the inputlookup command, but thisisn't the issue.

| inputlookup regions_instances.csv WHERE region=$site$ 
| fields instance instance_value

could you share the full code on both inputs?

Are you using Dashboard Classic or Dashboard Studio?

Ciao.

Giuseppe

0 Karma

ramana4u
Loves-to-Learn

Hi @gcusello 

// Here the full code

<fieldset submitButton="false">
<input type="dropdown" token="dccsite" searchWhenChanged="true">
<label>Choose Site</label>
<fieldForLabel>region</fieldForLabel>
<fieldForValue>region_value</fieldForValue>
<search>
<query>| inputlookup regions_instances.csv | fields region region_value | dedup region  region_value</query>
</search>
<default>express:dcceu:applog</default>
<initialValue>express:dcceu:applog</initialValue>
</input>
<input type="dropdown" token="dccinstance" searchWhenChanged="true">
<label>Choose Instance</label>
<fieldForLabel>instance</fieldForLabel>
<fieldForValue>instance_value</fieldForValue>
<search>
<query>|inputlookup regions_instances.csv | WHERE region=$dccsite$ | fields region region_value instance instance_value</query>
</search>
<default>/appl/dcc/dcceuexp/applogs/*</default>
<initialValue>/appl/dcc/dcceuexp/applogs/*</initialValue>
</input>
</fieldset>

//  regions_instances.csv

region,region_value,instance,instance_value
APEM,express:dcc:applog,Import,/appl/dcc/dccadm/applogs/*
APEM,express:dcc:applog,Export,/appl/dcc/dccexp/applogs/*
EU,express:dcceu:applog,Import,/appl/dcc/dcceu/applogs/*
EU,express:dcceu:applog,Export,/appl/dcc/dcceuexp/applogs/*
Trans,express:dcc:applog*,Import,/appl/dcc/dcceu/dcc2/applogs/*
Trans,express:dcc:applog*,Export,/appl/dcc/dcceuexp/dcc2/applogs/*
US,*express:dcc:applog,Import,/appl/dcc/dccus/applogs/*
US,*express:dcc:applog,Export,/appl/dcc/dccusexp/applogs/*

0 Karma

gcusello
Legend

Hi @ramana4u,

at first try to add quotes to the second input search:

| inputlookup regions_instances.csv | WHERE region="$dccsite$"

then please check if there a mistake between region and region_value maybe you have to use for the filter in the second input again region_value.

If it doesn'ìt run again try to add some asterisk at the beginning and the end of the condition.

| inputlookup regions_instances.csv | WHERE region="*$dccsite$*"

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...