<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Drilldown - Manipulate click.value before redirect in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Drilldown-Manipulate-click-value-before-redirect/m-p/166332#M10223</link>
    <description>&lt;P&gt;The same can be done in SimpleXML - output both columns in the table, refer to one column in the drilldown and hide the other column using CSS, something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;div#your_id table tr th:last-child, td:last-child {
  display: none;
}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note though, &lt;CODE&gt;chart count over A B by C&lt;/CODE&gt; is not valid. You'll need something like this instead:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval group = groupName."###".groupId | chart count over foo by source | rex field=foo "(?&amp;lt;groupName&amp;gt;.*)###(?&amp;lt;groupId&amp;gt;.*)" | fields - foo | table groupName *
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 01 Jan 2015 03:13:58 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2015-01-01T03:13:58Z</dc:date>
    <item>
      <title>Drilldown - Manipulate click.value before redirect</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Drilldown-Manipulate-click-value-before-redirect/m-p/166329#M10220</link>
      <description>&lt;P&gt;All,&lt;/P&gt;

&lt;P&gt;I have a dashboard panel to which I want to add a drilldown. The problem is that the value I display and the value I want to pass to the drilldown are different. To give you a sense, here's my search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Message="BrowserLogging" Browser="$browserId$"
| rename Data.GroupId as groupId 
| lookup groupIdToName groupId 
| chart count over groupName by Browser
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This search results in a table visualization. When I click on a row of that table, I want to use the groupId (not the displayed groupName) as the field that I pass to the drilldown. Right now I have the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;drilldown target="View by user"&amp;gt;
  &amp;lt;condition field="groupName"&amp;gt;
    &amp;lt;link&amp;gt;
      &amp;lt;![CDATA[
          /app/search/browser_usage_by_user?form.groupId=$click.value$&amp;amp;form.browserId=*&amp;amp;form.userId=*&amp;amp;form.monthVar.earliest=$monthVar.earliest$&amp;amp;form.monthVar.latest=$monthVar.latest$
          ]]&amp;gt;
    &amp;lt;/link&amp;gt;
  &amp;lt;/condition&amp;gt;
  &amp;lt;condition&amp;gt;
    &amp;lt;link&amp;gt;
      &amp;lt;![CDATA[
          /app/search/browser_usage_by_user?form.groupId=$click.value$&amp;amp;form.browserId=$click.name2$&amp;amp;form.userId=*&amp;amp;form.monthVar.earliest=$monthVar.earliest$&amp;amp;form.monthVar.latest=$monthVar.latest$
          ]]&amp;gt;
    &amp;lt;/link&amp;gt;
  &amp;lt;/condition&amp;gt;
&amp;lt;/drilldown&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The crucial thing that I want to do is take &lt;CODE&gt;$click.value$&lt;/CODE&gt; and manipulate it (convert it back to groupId) prior to passing it to the next dashboard.&lt;/P&gt;

&lt;P&gt;Is it possible to do this? Hopefully what I want to do makes sense. It's very similar to how a dropdown can have a "Label" and "Value" field on a dashboard.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2014 19:41:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Drilldown-Manipulate-click-value-before-redirect/m-p/166329#M10220</guid>
      <dc:creator>bruceclarke</dc:creator>
      <dc:date>2014-12-30T19:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown - Manipulate click.value before redirect</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Drilldown-Manipulate-click-value-before-redirect/m-p/166330#M10221</link>
      <description>&lt;P&gt;You could pass the &lt;CODE&gt;groupName&lt;/CODE&gt; to the other dashboard and have that dashboard search by the &lt;CODE&gt;groupId&lt;/CODE&gt; retrieved from that lookup of yours... that's assuming &lt;CODE&gt;groupName&lt;/CODE&gt; to &lt;CODE&gt;groupId&lt;/CODE&gt; is a 1:1 relationship.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2014 05:08:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Drilldown-Manipulate-click-value-before-redirect/m-p/166330#M10221</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-12-31T05:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown - Manipulate click.value before redirect</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Drilldown-Manipulate-click-value-before-redirect/m-p/166331#M10222</link>
      <description>&lt;P&gt;Just for reference, this is a case that's probably easier and simpler if you were using the Sideview XML instead of the Simple XML, becaue you can simply use the &lt;CODE&gt;hiddenFields&lt;/CODE&gt; param on the Table, and then refer to the hidden field in the Redirector with $click.fields.groupId$.   You'd have to familiarize yourself with the Sideview Utils app and it's techniques by reading some of the docs and examples that ship with the app.    &lt;A href="http://sideviewapps.com/apps/sideview-utils"&gt;http://sideviewapps.com/apps/sideview-utils&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...other things here like your Pulldown/Textarea/Radio/Checkbox module(s), and the main Search...
&amp;lt;module name="Search"&amp;gt;
  &amp;lt;param name="search"&amp;gt;
  Message="BrowserLogging" Browser="$browserId$"
   | rename Data.GroupId as groupId 
   | lookup groupIdToName groupId 
   | chart count over groupName groupId by Browser
  &amp;lt;/param&amp;gt;

  &amp;lt;module name="JobProgressIndicator"/&amp;gt;

  &amp;lt;module name="Pager"&amp;gt;

    &amp;lt;module name="Table"&amp;gt;
      &amp;lt;param name="hiddenFields"&amp;gt;groupId&amp;lt;/param&amp;gt;

      &amp;lt;module name="Redirector"&amp;gt;
        &amp;lt;param name="url"&amp;gt;/app/search/browser_usage_by_user&amp;lt;/param&amp;gt;
        &amp;lt;param name="arg.form.groupId"&amp;gt;$click.fields.groupId$&amp;lt;/param&amp;gt;
        &amp;lt;param name="arg.form.browserId"&amp;gt;*&amp;lt;/param&amp;gt;
        &amp;lt;param name="arg.form.userId"&amp;gt;*&amp;lt;/param&amp;gt;
        &amp;lt;param name="arg.form.monthVar.earliest"&amp;gt;$monthVar.earliest$&amp;lt;/param&amp;gt;
        &amp;lt;param name="arg.form.monthVar.latest"&amp;gt;$monthVar.latest$&amp;lt;/param&amp;gt;
      &amp;lt;/module&amp;gt;
    &amp;lt;/module&amp;gt;
  &amp;lt;/module&amp;gt;
&amp;lt;/module&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 31 Dec 2014 17:02:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Drilldown-Manipulate-click-value-before-redirect/m-p/166331#M10222</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2014-12-31T17:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown - Manipulate click.value before redirect</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Drilldown-Manipulate-click-value-before-redirect/m-p/166332#M10223</link>
      <description>&lt;P&gt;The same can be done in SimpleXML - output both columns in the table, refer to one column in the drilldown and hide the other column using CSS, something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;div#your_id table tr th:last-child, td:last-child {
  display: none;
}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note though, &lt;CODE&gt;chart count over A B by C&lt;/CODE&gt; is not valid. You'll need something like this instead:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval group = groupName."###".groupId | chart count over foo by source | rex field=foo "(?&amp;lt;groupName&amp;gt;.*)###(?&amp;lt;groupId&amp;gt;.*)" | fields - foo | table groupName *
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 01 Jan 2015 03:13:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Drilldown-Manipulate-click-value-before-redirect/m-p/166332#M10223</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-01-01T03:13:58Z</dc:date>
    </item>
  </channel>
</rss>

