Splunk Dev

A dropdown menu within a panel and change in the search query based on input selection

ssamant007
Explorer

I want to add a dropdown selection menu inside a dashboard panel using html and then based on the selected item from the dropdown , need to change the search query accordingly and results are updated in the chart visualization.

Example:

 Select Month:   All, Jan, Feb, ...Dec.

Now when user selects all, the query will display results for entire year (jan -dec) and when jan is selected then chart is displayed only showing the entire january data. Similarly for others.

I have other different panels within the dashboard under differet rows, and  I need to insert the drop down menu only for a specific panel. Also, my base search remains same irrespective of the drop-down selection, only the panel search string changes with change in the dropdown selection.

- any suggestion or guide would be a great help. It would be nice if it can be done with no or minimal use of JavaScript.

TIA

thanks

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Add a dropdown input to the row with the panel you want to filter and use the token from the dropdown in the search for that panel. The search can still be based on your initial search query, it is just applying some filtering.

View solution in original post

ssamant007
Explorer

Thanks @ITWhisperer  & @RickvdlJ . I built the solution based on the idea suggested.

0 Karma

RickvdIJ
Explorer

<row>

    <panel>

      <title>panel_in_dashboard</title>

      <input type="dropdown" token="hosttoken">

        <label>host-token</label>

        <fieldForLabel>host</fieldForLabel>

        <fieldForValue>host</fieldForValue>

        <search>

          <query>| tstats c where index=test by host | table host</query>

          <earliest>-15m@m</earliest>

          <latest>now</latest>

        </search>

      </input>

      <chart>

        <title>test</title>

        <search>

          <query>| tstats c where index=test host=$hosttoken$ by host</query>

          <earliest>-15m@m</earliest>

          <latest>now</latest>

        </search>

        <option name="charting.chart">line</option>

        <option name="charting.drilldown">none</option>

        <option name="refresh.display">progressbar</option>

      </chart>

    </panel>

 

-----

Now you have a dropdown menu in your dashboard panel with a token. This token is used in the panel-search.

Currently, the dropdown is populated by a search, but you can also include static values.

ITWhisperer
SplunkTrust
SplunkTrust

Add a dropdown input to the row with the panel you want to filter and use the token from the dropdown in the search for that panel. The search can still be based on your initial search query, it is just applying some filtering.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...