Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why am I unable to populate a token with the result of a search with my current Simple XML?

$
0
0
Hello there guys, I'm trying to populate a token with the result of a search so I'm able to use this value at various other points of the Dashboard. The search only has the field sourcetype at the end and it should populate the token "asas" with the sourcetype, based on the search result. This search runs and I'm able to see that it have more than zero results, based on the Job monitor. I'm using Splunk 6.2.2 and I was reading the "Search event handlers", but couldn't make it work. The point is that this token never gets the data set into it, maybe you someone could help me? **Dashboard code:** index=oneshot | head 1 | fields sourcetyperesults.sourcetypetruetesteeeee $asas$index="oneshot" search |head 1 | eval teste=$show_html$ | eval gethim=$asas$ | table GrupoNome2,gethim
asasasas
teste - $asas$

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>