I'm in the process of building out a new dashboard that will have 3 input selects.
1. Datetime
2. Input1
3. Input2
Input1 is dependent on Datetime and input2 is dependent on input1. I'm using search strings to set all 3 inputs but I need to have it setup populate the drop downs for input1 and 2. This way everything in the dashboard will only return results for the values that are in the drop downs. I know I can do an earliest latest in my search but I'd rather have input1 derive its data from the datetime selector. I don't see an option in the time selector values to tie it back to a token like when you add a search to a panel.
We're currently on Splunk 7.0.3
Thank you for your assistance.
↧