Dashboards & Visualizations

How to get dashboard search textfield working with lookup values or values of ip location

david1395
New Member

I have a table in my dashboard:
my search*********

"$search_field$"
|lookup customer.csv license_hash as license_hash OUTPUT customer_id customer_name
|ip location client_ip
|table customer_id,customer_name,client_ip.......

In the dashboard I have a search field and on the table a drill down on this search field.

The problem: w
When I click on values of customer_id,client_ip, City,_Customer_name.....
I get no results....of course not because of the lookup after the search field in the search.

Wich changes I have to do to make it possible to search with this values?

to add |search "§search_field§" after the lookup doesn't work.

0 Karma

DalJeanis
Legend

You are taking an input record, then using the input field license_hash to look that up and get customer_id and customer_name

It looks like you then intend to use command iplocation to look up the location info from the field client_ip. however, at that point you don't appear to actually have a field named client_ip. Is that in the initial event record, or is it in the lookup table, or is it nowhere?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...