Dashboards & Visualizations

How to build a multi-input dashboard and ignore inputs that are left blank?

Glasses
Builder

Hi 

I am trying to build a multi-input textbox dashboard based on a KVstore lookup.

My query is like this

 

| inputlookup <some-host-detail-kvlookup>
| search $computer_name$ OR $computer_number$ OR $computer_id$
| fields computerName computerNumber ComputerId ... 

 

each token has a prefix i.e. <fieldName> =  (which is the column header field in the lookup)

each token also has an initial value = null 

thus the query runs like this 

 

 

| search computerName=null OR computerNumber=null OR ComputerId=null

| search computerName=FOO  OR computerNumber=null OR ComputerId=null

 

 

as you can see setting  the <fieldName> to null allows the search to run without breaking, but after a user enters FOO for the computerName value, they need to reset the blank search inputs back to null.   Otherwise if a blank is passed like 

 

| search computerName= OR computerNumber=null OR ComputerId=null

 

the search breaks.

 

Any suggestions how to ignore the empty inputs or a way to reset the initial values to null again is greatly appreciated.  OR if anyone has a suggestion to do this another way, I would very much like to hear.

Thank you

0 Karma
Get Updates on the Splunk Community!

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...