I been looking for a while now for an answer , I have read just about everything but I am not getting what I am lookin for.
My first panel search is simply an Inputlookup csv predefined in Splunk that updates nightly with new data..
The user controls the results table with the time picker....what ever dates they choose a table is produced.... so far so good....
What I want to do is grab an entire column/ field that's returned and use all the values in a second panel...
Just simply being able to use | Table $Customers$ in the second panel or use that list with a where clause in second panel....
I don't want a drill down or click value or anything I just want to use the whole list / column in the second panel.. nothing fancy
my code..
| inputlookup Customers_2019.csv
| search = "Products" = sold
| eval _time = Purchase_date
| sort - DateCreated
| table Customers
which produces the list I want...
I want to simply pass the Customers to a token to use later..
... View more