Dashboards & Visualizations

Set token in XML dashboard based on result count in scheduled report

sssignals
Path Finder

Hi Splunk community

I have a scheduled report running every 5 mins that ends with "... | stats count". Is there a way based on result count > 0, set token to true in XML dashboard in order to show the panel that depends on the token.

Thanks in advance.

0 Karma

gaurav_maniar
Builder

Hi,

You can add a hidden panel with saved search and use the result count in other search,

<row depends="$hidden$">
    <panel>
      <table>
        <title>Report Name</title>
        <search ref="Saved Search or Alert Name">
          <done>
            <set token="test">$job.resultCount$</set>
          </done>
        </search>
      </table>
    </panel>
  </row>
  <row>
    <panel>
      <table>
        <search>
          <query>| makeresults | eval test=$test$</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
        </search>
      </table>
    </panel>
  </row>

Accept & up-vote the answer if it helps.

happy splunking.....!!!!

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@sssignals

Here, I suggest you store count in any lookup and use in your dashbaord to set token.

Like.

.... | stats count | oputputlookup my_lookup

Access lookup data using | inputlookup my_lookup | table count and set token in the dashboard.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...