<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic creating drilldown panel based on the selected value in $click.value$ in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/creating-drilldown-panel-based-on-the-selected-value-in-click/m-p/497036#M8635</link>
    <description>&lt;P&gt;I want to create a drilldown panel that will run different searches based on the value selected i.e. $click.value$.&lt;/P&gt;

&lt;P&gt;search for panel 1 is something like-&lt;BR /&gt;
&lt;STRONG&gt;my query| top sourcetype&lt;/STRONG&gt;&lt;BR /&gt;
user will click on a sourcetype and then a new panel will come up and i want to give a table with relevant fields based on the selected sourcetype. For example, if the selected sourcetype is firewall, we need to give src dest session_id etc and if the sourcetype is mailbox we need to give sender_email_id receiver_email_id  etc.&lt;/P&gt;

&lt;P&gt;So, i want to execute table command in my panel 2 based on the sourcetype under consideration.&lt;/P&gt;

&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1406"&gt;@woodcock&lt;/a&gt; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/172209"&gt;@mayurr98&lt;/a&gt; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/182766"&gt;@rmmiller&lt;/a&gt; please help!!&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 03:11:22 GMT</pubDate>
    <dc:creator>ManishVilla7</dc:creator>
    <dc:date>2020-09-30T03:11:22Z</dc:date>
    <item>
      <title>creating drilldown panel based on the selected value in $click.value$</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/creating-drilldown-panel-based-on-the-selected-value-in-click/m-p/497036#M8635</link>
      <description>&lt;P&gt;I want to create a drilldown panel that will run different searches based on the value selected i.e. $click.value$.&lt;/P&gt;

&lt;P&gt;search for panel 1 is something like-&lt;BR /&gt;
&lt;STRONG&gt;my query| top sourcetype&lt;/STRONG&gt;&lt;BR /&gt;
user will click on a sourcetype and then a new panel will come up and i want to give a table with relevant fields based on the selected sourcetype. For example, if the selected sourcetype is firewall, we need to give src dest session_id etc and if the sourcetype is mailbox we need to give sender_email_id receiver_email_id  etc.&lt;/P&gt;

&lt;P&gt;So, i want to execute table command in my panel 2 based on the sourcetype under consideration.&lt;/P&gt;

&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1406"&gt;@woodcock&lt;/a&gt; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/172209"&gt;@mayurr98&lt;/a&gt; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/182766"&gt;@rmmiller&lt;/a&gt; please help!!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:11:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/creating-drilldown-panel-based-on-the-selected-value-in-click/m-p/497036#M8635</guid>
      <dc:creator>ManishVilla7</dc:creator>
      <dc:date>2020-09-30T03:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: creating drilldown panel based on the selected value in $click.value$</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/creating-drilldown-panel-based-on-the-selected-value-in-click/m-p/497037#M8636</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;drilldown&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal |top sourcetype&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;drilldown&amp;gt;
          &amp;lt;set token="sourcetype"&amp;gt;$row.sourcetype$&amp;lt;/set&amp;gt;
        &amp;lt;/drilldown&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row depends="$sourcetype$"&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal sourcetype="$sourcetype$"&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 05 Dec 2019 03:31:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/creating-drilldown-panel-based-on-the-selected-value-in-click/m-p/497037#M8636</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-12-05T03:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: creating drilldown panel based on the selected value in $click.value$</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/creating-drilldown-panel-based-on-the-selected-value-in-click/m-p/497038#M8637</link>
      <description>&lt;P&gt;we have to execute &lt;STRONG&gt;different table commands based on the value of the sourcetype&lt;/STRONG&gt;, this is just passing sourcetype. I want that if the value of $sourcetype$ is ! then table A runs in panel 2, if sourcetype is B then table B runs.  &lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 03:56:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/creating-drilldown-panel-based-on-the-selected-value-in-click/m-p/497038#M8637</guid>
      <dc:creator>ManishVilla7</dc:creator>
      <dc:date>2019-12-05T03:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: creating drilldown panel based on the selected value in $click.value$</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/creating-drilldown-panel-based-on-the-selected-value-in-click/m-p/497039#M8638</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Check this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;drilldown&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal |top sourcetype&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;drilldown&amp;gt;
          &amp;lt;condition match="'row.sourcetype' == &amp;amp;quot;mongod&amp;amp;quot;"&amp;gt;
            &amp;lt;set token="sourcetype"&amp;gt;$row.sourcetype$&amp;lt;/set&amp;gt;
            &amp;lt;set token="table"&amp;gt;|table date_hour,date_mday,date_second&amp;lt;/set&amp;gt;
          &amp;lt;/condition&amp;gt;
           &amp;lt;condition match="'row.sourcetype' == &amp;amp;quot;splunkd&amp;amp;quot;"&amp;gt;
            &amp;lt;set token="sourcetype"&amp;gt;$row.sourcetype$&amp;lt;/set&amp;gt;
            &amp;lt;set token="table"&amp;gt;|table group,name&amp;lt;/set&amp;gt;
          &amp;lt;/condition&amp;gt;
          &amp;lt;condition&amp;gt;&amp;lt;/condition&amp;gt;
        &amp;lt;/drilldown&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row depends="$sourcetype$"&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal sourcetype="$sourcetype$" $table$&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 05 Dec 2019 09:35:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/creating-drilldown-panel-based-on-the-selected-value-in-click/m-p/497039#M8638</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-12-05T09:35:33Z</dc:date>
    </item>
  </channel>
</rss>

