Hi @hishamjan You will need to add a field to your search query to include the selected host from your dropdown. For example, if the token from the dropdown was named "selected_host" then you would modify the search query for the panel to be: source="vmstat" host=$selected_host$
| dedup host
| eval host=upper(host)
| eval FreeGBs=FreeMBytes/1024, TotalGBs=TotalMBytes/1024, UsedGBs=UsedMBytes/1024
| table host memFreePct memUsedPct And you will need to modify the dropdown to assign a value or an "*" (for no selected hosts) to the token "selected_host". the Splunk documentation for Create and edit forms would be a great place to review those settings. One more thing to consider, if you want to view the data over time, then you will probably want to modify the search query for your panel to be populated by a timechart instead of eval/table. source="vmstat" host=$selected_host$
| eval host=upper(host)
| eval FreeGBs=FreeMBytes/1024, TotalGBs=TotalMBytes/1024, UsedGBs=UsedMBytes/1024
|timechart avg(memFreePct) as memFreePct, avg(memUsedPct) as memUsedPct by $selected_host$ Hope that helps.
... View more