I have a dashboard created with network data already in that dashboard. I am trying to create a search dropdown or search bar so I can search for a specific IP and it will show all the data for that IP in my dashboard.
If you're using simpleXML dashboards, then simply add a text form input and assign it a token and use that token in your search
<search>
<query>your search... ip=$ip_text$</query>
</search>
Thanks, bowesmana,
I am new to Splunk I am trying to figure out the query for my search I am using a pivot search and when I put
ip=$ip_text$
It tells me Error in 'PivotProcessor': Error in 'PivotCell': The dataset 'RootObject' has no field 'IP='. I am wondering if I am doing the search wrong.
Are you using the pivot report and trying to add a filter or creating and classic (XML) or dashboard studio dashboard?
Yes I am using the pivot report and trying to add a filter.