Dashboards & Visualizations

Populating Form Dropdowns via searches

mcwomble
Path Finder

I have a question regarding the population of dropdowns via saved searches.

The examples in the Splunk documentation show a search similar to the following:

   <populatingSearch fieldForValue="suser" fieldForLabel="suser"><!CDATA[sourcetype=p4change | rex "user=(?<suser>\w+)@" | stats count by suser]]></populatingSearch>

However, I am slightly confused (maybe because the search in the examples is quite complex) on how this is carried out in practice.

I wish to populate the dropdown with the contents of the partner field which has up to 200 different values within the indexed data. The string being as follows:

2010/12/13@13:31:22,billstats,partner=XXXX,cde=XX,usd=XX

How would I write the example population string in a way which can parse my indexed data in a way that could populate the dropdown?

Tags (1)
0 Karma
1 Solution

ziegfried
Influencer
<populatingSearch fieldForValue="partner" fieldForLabel="partner">
    sourcetype=your_sourcetype | fields partner | dedup partner
</populatingSearch>

View solution in original post

ziegfried
Influencer
<populatingSearch fieldForValue="partner" fieldForLabel="partner">
    sourcetype=your_sourcetype | fields partner | dedup partner
</populatingSearch>

mcwomble
Path Finder

Brilliant! That works a treat

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...