Hi Splunk community
I have a scheduled report running every 5 mins that ends with "... | stats count". Is there a way based on result count > 0, set token to true in XML dashboard in order to show the panel that depends on the token.
Thanks in advance.
Hi,
You can add a hidden panel with saved search and use the result count in other search,
<row depends="$hidden$">
<panel>
<table>
<title>Report Name</title>
<search ref="Saved Search or Alert Name">
<done>
<set token="test">$job.resultCount$</set>
</done>
</search>
</table>
</panel>
</row>
<row>
<panel>
<table>
<search>
<query>| makeresults | eval test=$test$</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
</table>
</panel>
</row>
Accept & up-vote the answer if it helps.
happy splunking.....!!!!
@sssignals
Here, I suggest you store count in any lookup and use in your dashbaord to set token.
Like.
.... | stats count | oputputlookup my_lookup
Access lookup data using | inputlookup my_lookup | table count
and set token in the dashboard.