Dashboards & Visualizations

Use SearchSelectLister to select a field and ExtendedFieldSearch to input the value for the selected field

aputz
Path Finder

Hello,
I already have SearchSelectListers and ExtendedFieldSearches implemented in a couple dashboards and was wondering if an idea for joining them is possible.

Ideally I want to have a SearchSelectLister which will populate a drop-down with potential fields (source ip, dest ip, etc.) followed by an ExtendedFieldSearch which is where the user can input the value for the selected field.

So my primary question is how I would get the SearchSelectLister to talk with the ExtendedFieldSearch. Would I be able to use addterm for the intention with SearchSelectLister and then use stringreplace with the ExtendedFieldSearch to insert the value? That's an idea I have in my head but I don't think it'll work based on how I've used addterm before.

I wanted to see if anyone else has tried this before with what's available out of the box before checking into the Sideview Utils app.

Also as a last thing if I am able to get this to work I would then want to be able to have three of these nested and possibly have a drop-down to select "AND" or "OR" between each pair of SearchSelectLister and ExtendedFieldSearch modules.

Thank you very much for any help on this.

RicoSuave
Builder

This is all possible with Sideview Utils. Download it and play with the examples. And say goodbye to intentions 🙂

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...