Dashboards & Visualizations

How to get dashboard search textfield working with lookup values or values of ip location

david1395
New Member

I have a table in my dashboard:
my search*********

"$search_field$"
|lookup customer.csv license_hash as license_hash OUTPUT customer_id customer_name
|ip location client_ip
|table customer_id,customer_name,client_ip.......

In the dashboard I have a search field and on the table a drill down on this search field.

The problem: w
When I click on values of customer_id,client_ip, City,_Customer_name.....
I get no results....of course not because of the lookup after the search field in the search.

Wich changes I have to do to make it possible to search with this values?

to add |search "§search_field§" after the lookup doesn't work.

0 Karma

DalJeanis
Legend

You are taking an input record, then using the input field license_hash to look that up and get customer_id and customer_name

It looks like you then intend to use command iplocation to look up the location info from the field client_ip. however, at that point you don't appear to actually have a field named client_ip. Is that in the initial event record, or is it in the lookup table, or is it nowhere?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...