Hi,
I have made this in Splunk 6.5.2 and now I'm wondering how to pass the two tokens (host and nt_username) to the report ?
Thanx in advance
<form>
<label>Test Gunther</label>
<fieldset submitButton="false" autoRun="false">
<input type="dropdown" token="host">
<label>Server</label>
<choice value="*"><ALL></choice>
<default>*</default>
<fieldForLabel>host</fieldForLabel>
<fieldForValue>host</fieldForValue>
<search>
<query>index=dbx_sqldba sourcetype=extevent | eval sql_text="host" | table host |dedup host | sort host</query>
<earliest>0</earliest>
<latest></latest>
</search>
</input>
<input type="dropdown" token="nt_username">
<label>User Name</label>
<choice value="*"><ALL></choice>
<search>
<query>index=dbx_sqldba sourcetype=extevent host=$host$ | eval sql_text="nt_username" | table nt_username | dedup nt_username | sort nt_username</query>
<earliest>0</earliest>
<latest></latest>
</search>
<default>*</default>
<fieldForLabel>nt_username</fieldForLabel>
<fieldForValue>nt_username</fieldForValue>
</input>
</fieldset>
<row>
<panel>
<chart>
<title>Test_Gunther2</title>
<search ref="Test_Gunther2"></search>
<option name="charting.axisLabelsX.majorLabelStyle.overflowMode">ellipsisNone</option>
<option name="charting.axisLabelsX.majorLabelStyle.rotation">-45</option>
<option name="charting.axisTitleX.text">Datum</option>
<option name="charting.axisTitleY.text">Aantal Queries</option>
</chart>
</panel>
</row>
</form>