Splunk Enterprise

How could I show the value in my data in the drop down?

Questioner
Path Finder

I want to show the drop down value automatically about data name "landing_time".

So I wrote my code like this.

| eval st_time= round(landing_time,0)
| where st_time<=90
| stats values by st_time
| sort st_time

 But it show all landing_time less than 90, not fil the landing_time. For example..

lading_time : 7, 15, 17, 24, 30..
drop down data show : 0, 1, 2, 3, 4, .......17, 18, 19,....30, 31...

 How could I show only landing_time in the drop down?

Labels (1)
Tags (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Change you fieldForLabel and fieldForValue attributes

   <fieldForLabel>st_time</fieldForLabel>
   <fieldForValue>st_time</fieldForValue>

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please share your dashboard source code in a code block

0 Karma

Questioner
Path Finder

This is my code about the drop down

<input type="dropdown" token="start_time" searchWhenChanged="true">
<label>First IR init Time (sec)</label>
<fieldForLabel>start_time</fieldForLabel>
<fieldForValue>start_time</fieldForValue>
<search>
<query>index=idx_ptd_dataset sourcetype="type:ptd_dataset:data" corp="flight"
| where !isnull(location)
| where !isnull(landing_time)
| eval st_time= round(landing_time,0)
| where st_time &lt;=90
| stats values by st_time
| sort st_time</query>
</search>
<default>ALL</default>
<choice value="ALL">ALL</choice>
</input>

 

 



 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Change you fieldForLabel and fieldForValue attributes

   <fieldForLabel>st_time</fieldForLabel>
   <fieldForValue>st_time</fieldForValue>
0 Karma

Questioner
Path Finder

Thank you for you help!
It work!!

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...