Dashboards & Visualizations

How to populate the values of a drop-down based on the value selected in another drop-down?

xvxt006
Contributor

Hi,

I have 2 drop-downs in a form on a dashboard. Based on what i select in the first drop-down, I want it to dictate the values in the 2nd drop-down. How can this be done? any examples, suggestions available?

Tags (1)
0 Karma

splunker12er
Motivator

Did you checked out sideview utils app ?

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Yes, see Form examples in the documentation for a written description, and download the Splunk 6.x Dashboard Examples app for an implemented example.

xvxt006
Contributor

Thank you. I will try this and let you know.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Same basic strategy, just with a small detour.

Define your first dropdown static as you normally would.
Define your second dropdown dynamic with a search like this:

| stats count | eval values = "one two three four five" | makemv values | mvexpand values

That gives you a static list of five values. You can now append filters based on your first value like this:

... | where "$firstvalue$"="foo" OR values="one" OR values="two" OR values="three"

That would keep all values if the first selected value is "foo", and keep only the first three values if it's not.

xvxt006
Contributor

Form examples show how to populate data dynamically. But in my case, dropdown values are static only. for example when i select first value from first dropdown, all values from 2nd dropdown are applicable. But when i select 2nd value from first drop down, only subset of values from 2nd dropdown are applicable. Do you know how to achieve this?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...