Hello,
I am building a small splunk app and I have a dashboard that has many tables with inline searches like this:
app2audit AND (Instance=USCASF) AND (Period=201009)| eval Date=_time | convert timeformat="%Y%m%d-%H:%M" ctime(Date) | table Date, Host, Artifact, Size, LastMod | sort Date
What I would like to do is put a html row that has a combo box with a list like: 201009, 201010, 201011, 201012.
And then when I select one option from the html combo box it passes the variable to the "Period" field in the inline search in all the tables and updates the tables.
Is that possible?
Absolutely. It sounds like a Lister module would work very well. I'd suggest looking at the UI examples app from splunkbase. There are a wide variety of examples of how to use it. But in short:
app2audit Instance=USCASF | stats count by Period | sort - Period
Absolutely. It sounds like a Lister module would work very well. I'd suggest looking at the UI examples app from splunkbase. There are a wide variety of examples of how to use it. But in short:
app2audit Instance=USCASF | stats count by Period | sort - Period