Splunk Search

asking for a an ID before searching

lancealotx
Explorer

I have a few queries, dashboards, and now being asked to take it up a notch. We hava a bunch of data points, and I'm being asked for some reports based on different ones but real time. Basically they want to goto a place, enter an ID, hit enter and have a report and/or results based on that. Right now the dashboard and reports are more general.

So I am wondering if this is a 'app' I have to write? Trying to know where to start my reading, but for the proof of concept, I would like to just have him hit something, have a form box. They can type 1234 and have the results set populate WHERE id = what was entered.

So where do I start my journey?

- - tnx - -

Tags (1)
0 Karma
1 Solution

Ayn
Legend

I would start reading about forms with simple XML here: http://docs.splunk.com/Documentation/Splunk/latest/Developer/FormIntro

And get more examples by downloading the UI examples app: splunk-base.splunk.com/apps/22333/splunk-ui-examples-app-for-41

View solution in original post

lancealotx
Explorer

Exactly what I needed, the push in the right direction. Starting my reading now!

0 Karma

Ayn
Legend

I would start reading about forms with simple XML here: http://docs.splunk.com/Documentation/Splunk/latest/Developer/FormIntro

And get more examples by downloading the UI examples app: splunk-base.splunk.com/apps/22333/splunk-ui-examples-app-for-41

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...