Dashboards & Visualizations

How to populate the values of a drop-down based on the value selected in another drop-down?

xvxt006
Contributor

Hi,

I have 2 drop-downs in a form on a dashboard. Based on what i select in the first drop-down, I want it to dictate the values in the 2nd drop-down. How can this be done? any examples, suggestions available?

Tags (1)
0 Karma

splunker12er
Motivator

Did you checked out sideview utils app ?

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Yes, see Form examples in the documentation for a written description, and download the Splunk 6.x Dashboard Examples app for an implemented example.

xvxt006
Contributor

Thank you. I will try this and let you know.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Same basic strategy, just with a small detour.

Define your first dropdown static as you normally would.
Define your second dropdown dynamic with a search like this:

| stats count | eval values = "one two three four five" | makemv values | mvexpand values

That gives you a static list of five values. You can now append filters based on your first value like this:

... | where "$firstvalue$"="foo" OR values="one" OR values="two" OR values="three"

That would keep all values if the first selected value is "foo", and keep only the first three values if it's not.

xvxt006
Contributor

Form examples show how to populate data dynamically. But in my case, dropdown values are static only. for example when i select first value from first dropdown, all values from 2nd dropdown are applicable. But when i select 2nd value from first drop down, only subset of values from 2nd dropdown are applicable. Do you know how to achieve this?

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...