Hi
Check this sample and use base search
<form>
<label>filter</label>
<search id="base_query">
<query>index="_internal" |table source,host,sourcetype,splunk_server</query>
<earliest>$timepicker.earliest$</earliest>
<latest>$timepicker.latest$</latest>
</search>
<fieldset submitButton="false">
<input type="time" token="timepicker">
<label></label>
<default>
<earliest>-24h@h</earliest>
<latest>now</latest>
</default>
</input>
<input type="dropdown" token="host">
<label>host</label>
<search base="base_query">
<query>|stats count by host</query>
</search>
<fieldForLabel>host</fieldForLabel>
<fieldForValue>host</fieldForValue>
<prefix>host="</prefix>
<suffix>"</suffix>
</input>
</fieldset>
<row>
<panel>
<table>
<search base="base_query">
<query>
|search $host$ |stats count by source
</query>
</search>
</table>
</panel>
</row>
</form>
... View more