Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why is my dynamic input drop-down displaying one comma separated string instead of discrete values?

$
0
0
I'm creating a dashboard to help less technical operators evaluate the contents of our indexes so that we can restructure the roles and data access. This is the source as stands today (the search will be replaced by a report performing the same search once a day):
index=* OR index=_* | stats values(index) AS indexname | eval label=indexname | table indexname, label-15mnowlabelindexname
Hosts and Sourcesindex="$index_name$" | eval host_and_source=(host . " | " . source) | stats values(host_and_source) AS "Hosts and Sources"-15mnow
What is absolutely driving me crazy right now is the drop-down is a comma separated string of all of the indexes. I'm not getting discrete values to select, I'm getting a great big string of garbage. WHY?!?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>