Dashboards & Visualizations

Dashboard not working

svemurilv
Path Finder

Hi
I have multiple apps in our environment each app represents ApplicationDomain, and all of them have lots of dashboards , where we are using a lookup table values to populate the ApplicationDomain values in the Drop-down. A few ApplicationDomain Names have a space in between the name. where my dashboard global token $emnv:arpp$

AppName : PGR - External Data
AppFoldername is : ExternalData

<form>
  <label>RRD Restarts Clone__test</label>
  <fieldset autoRun="false" submitButton="true">

    <input type="dropdown" token="domain">
      <label>Application Domain</label>
      <search>
        <query>|inputlookup ApplicationDomain.csv|stats  count by ApplicationDomain |sort +ApplicationDomain</query>
        <earliest>-24h@h</earliest>
        <latest>now</latest>
      </search>
      <fieldForValue>ApplicationDomain</fieldForValue>
      **<choice value="$env:anpp$">default</choice>**
    </input>

How can i work this code for the ApplicationDomain name has space?

Tags (3)
0 Karma
1 Solution

somesoni2
SplunkTrust
SplunkTrust

Try this for your dropdown

<input type="dropdown" token="domain">
       <label>Application Domain</label>
       <search>
         <query>|inputlookup ApplicationDomain.csv|stats  count by ApplicationDomain | eval rank=if(match(replace(ApplicationDomain," ",""),"$env:app$"),1,0)|sort -rank +ApplicationDomain | fields - rank</query>
         <earliest>-24h@h</earliest>
         <latest>now</latest>
       </search>
       <fieldForValue>ApplicationDomain</fieldForValue>
       <selectFirstChoice>true</selectFirstChoice>
     </input>

Basically comparing the global token value with ApplicationDomain field with space removed (just for comparision, original value unchanged) and whever matched with place in first place in the dropdown (sort logic using rank). Then configuring dropdown to select the first value by default using <selectFirstChoice> option.

View solution in original post

somesoni2
SplunkTrust
SplunkTrust

Try this for your dropdown

<input type="dropdown" token="domain">
       <label>Application Domain</label>
       <search>
         <query>|inputlookup ApplicationDomain.csv|stats  count by ApplicationDomain | eval rank=if(match(replace(ApplicationDomain," ",""),"$env:app$"),1,0)|sort -rank +ApplicationDomain | fields - rank</query>
         <earliest>-24h@h</earliest>
         <latest>now</latest>
       </search>
       <fieldForValue>ApplicationDomain</fieldForValue>
       <selectFirstChoice>true</selectFirstChoice>
     </input>

Basically comparing the global token value with ApplicationDomain field with space removed (just for comparision, original value unchanged) and whever matched with place in first place in the dropdown (sort logic using rank). Then configuring dropdown to select the first value by default using <selectFirstChoice> option.

svemurilv
Path Finder

alt textHi somesh,
its sorting by rank but still the default value not displaying with space.
my original lookup file and application Domain value indexed with space.

https://splunk-usergroups.slack.com/files/vemchow/F551EJ3FS/capture122.jpg

0 Karma

svemurilv
Path Finder

Hi sorry somesh,
My browser cookies spam, its working after changing the browser

0 Karma

somesoni2
SplunkTrust
SplunkTrust

Glad it worked out for you. Don't forget to close the question in case there is no follow-up question related to this.

0 Karma

somesoni2
SplunkTrust
SplunkTrust

The value parameter should have exact same values as it appear in lookup table. The global token will give you folder name, not the display name. The lookup also seem to have additional prefix. Where and how is your domain token is being used?

0 Karma

svemurilv
Path Finder

am using this Application Domain in my entire Dashboard searches
how can i use this i dont know how we can use this to get the app name may app are looking like BEP:Application Name and in my lookup table Application Domain was like Application Name and app dir name was ApplicationName

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...