From 7462a749b64fdfc7d140ba2d87738d51052b71ca Mon Sep 17 00:00:00 2001 From: Scott Horton Date: Mon, 21 Sep 2026 17:38:34 -0500 Subject: [PATCH 1/4] Fix lookup lists, dropdown clipping, and search overhead --- CHANGELOG.md | 7 + DEPLOYMENT.md | 6 +- frontend/src/LookupField.tsx | 257 ++++++++++++------ frontend/src/MultiInput.tsx | 40 +-- frontend/src/lookup-search.js | 14 + frontend/src/multi-values.js | 16 ++ frontend/src/styles.css | 7 +- package-lock.json | 4 +- package.json | 2 +- splunk_actionstack/bin/actionstack/lookups.py | 21 +- splunk_actionstack/bin/actionstack/service.py | 13 +- splunk_actionstack/default/app.conf | 2 +- tests/lookup-search.test.mjs | 17 ++ tests/multi-values.test.mjs | 15 + tests/test_lookup_pipelines.py | 9 + tests/test_management_lookups.py | 23 ++ 16 files changed, 339 insertions(+), 114 deletions(-) create mode 100644 frontend/src/multi-values.js create mode 100644 tests/multi-values.test.mjs diff --git a/CHANGELOG.md b/CHANGELOG.md index 31de4d7..5b17284 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,12 @@ # Changelog +## 0.5.2 + +- Accept comma-, newline-, and semicolon-separated lists in multiple-value text and lookup fields. Lookup lists are checked together before adding, and duplicate values are removed. +- Keep lookup suggestions inside the form layout so results are not clipped at the bottom of a panel. +- Allow `local=true` and `local=false` before or after the inputlookup name. +- Reduce lookup overhead by skipping occupied rate-limit slots, waiting for search completion during dispatch, and caching recent suggestions for 30 seconds. Submission still revalidates lookup values. + ## 0.5.1 - Set `is_configured = false` in the distributed app configuration. diff --git a/DEPLOYMENT.md b/DEPLOYMENT.md index e537d83..ab08dd8 100644 --- a/DEPLOYMENT.md +++ b/DEPLOYMENT.md @@ -67,9 +67,11 @@ Single-value and multiple-value lookup fields run SPL as the requesting Splunk u Set **Value field sent to SOAR** to `identity` and **Display label field** to `display_name`. Keep both in the final results. Suggestions match either field; only selected values are submitted and revalidated. -Searches must start with `inputlookup`. Supported transformations are `eval`, `where`, `search`, `fields`, `table`, `rename`, `dedup`, `sort`, `head`, `tail`, `fillnull`, `rex`, `regex`, `spath`, `stats`, `eventstats`, `streamstats`, `mvexpand`, `makemv`, `mvcombine`, `nomv`, `convert`, and `replace`. Macros, subsearches, custom commands, and write commands are not supported. +Searches must start with `inputlookup`. ActionStack accepts `local=true` or `local=false` before or after the lookup name and passes it through to Splunk. Supported transformations are `eval`, `where`, `search`, `fields`, `table`, `rename`, `dedup`, `sort`, `head`, `tail`, `fillnull`, `rex`, `regex`, `spath`, `stats`, `eventstats`, `streamstats`, `mvexpand`, `makemv`, `mvcombine`, `nomv`, `convert`, and `replace`. Macros, subsearches, custom commands, and write commands are not supported. -The default search delay is 50 ms after at least three characters. Results are limited to 25 prefix matches. Search jobs have a five-second execution limit. Each form supports up to five lookup fields; multiple-value fields accept up to 25 items. Large lookups may require scans even when results are limited. +The default search delay is 50 ms after at least three characters. Results are limited to 25 prefix matches. Search jobs have a five-second execution limit. Each form supports up to five lookup fields; multiple-value fields accept up to 25 items. Recent suggestions are cached in the field for 30 seconds; submission checks always run against the lookup again. Large lookups may require scans even when results are limited. + +Multiple-value text and lookup fields accept comma-, newline-, or semicolon-separated lists. Paste a list, or type it and press Enter or **Add values**. For lookups, use exact values from the configured SOAR value field; use search suggestions to select by display label. A batch with unknown values is rejected without adding a partial list. Duplicate values are removed. ## Permissions diff --git a/frontend/src/LookupField.tsx b/frontend/src/LookupField.tsx index 839880e..dd3a831 100644 --- a/frontend/src/LookupField.tsx +++ b/frontend/src/LookupField.tsx @@ -2,6 +2,7 @@ import { useEffect, useRef, useState } from "react"; import { ValueChips } from "./MultiInput"; import { api } from "./api"; import { lookupSearch } from "./lookup-search.js"; +import { mergeValues } from "./multi-values.js"; import type { Field, Form, LookupConfig } from "./types"; export const defaultLookup: LookupConfig = { search: "| inputlookup identity_lookup_expanded | fields identity", @@ -31,9 +32,10 @@ export function LookupSettings({ onChange={(e) => change({ search: e.target.value })} /> - Start with | inputlookup lookup_name. Add read-only SPL such as eval, - where, rename, table or stats. Keep both result fields in the output. - Macros, subsearches and commands that write data are not supported. + Start with | inputlookup lookup_name (local=true is allowed). Add + read-only SPL such as eval, where, rename, table or stats. Keep both + result fields in the output. Macros, subsearches and commands that + write data are not supported.