<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to link two dashboards in splunk 6.2 in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253038#M15771</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have two different dashboards one for disk space usage and other for memory and CPU utilization for two different hosts. I want to link them so that if i select one host in drill down so automatically its shows me the other KPI values also so is there any way to do this. Please give your valuable suggestions.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 30 Nov 2015 11:02:39 GMT</pubDate>
    <dc:creator>sunnyparmar</dc:creator>
    <dc:date>2015-11-30T11:02:39Z</dc:date>
    <item>
      <title>how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253038#M15771</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have two different dashboards one for disk space usage and other for memory and CPU utilization for two different hosts. I want to link them so that if i select one host in drill down so automatically its shows me the other KPI values also so is there any way to do this. Please give your valuable suggestions.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 11:02:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253038#M15771</guid>
      <dc:creator>sunnyparmar</dc:creator>
      <dc:date>2015-11-30T11:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253039#M15772</link>
      <description>&lt;P&gt;Just a small suggestion  : Have you tried using different panels on the same dashboard? It should give you an overall idea about all the metrics at a glance.&lt;/P&gt;

&lt;P&gt;For two different dashboard, you can use drill down to pass the host value to the second dashboard and use it on that dashboard&lt;/P&gt;

&lt;P&gt;For eg:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;table&amp;gt;
  &amp;lt;title&amp;gt;Details&amp;lt;/title&amp;gt;
  &amp;lt;search&amp;gt; &amp;lt; search terms&amp;gt;&amp;lt;/search&amp;gt;
  &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
  &amp;lt;option name="&amp;lt;something"&amp;gt;&amp;lt;something&amp;gt;&amp;lt;/option&amp;gt; 
  &amp;lt;drilldown&amp;gt;
    &amp;lt;link&amp;gt;/app/&amp;lt;appname&amp;gt;/&amp;lt;page name&amp;gt;?form.index=$row.index$&amp;amp;amp;form.host=$row.host$&amp;amp;amp&amp;lt;/link&amp;gt;
  &amp;lt;/drilldown&amp;gt;
  &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
&amp;lt;/table&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 04 Dec 2015 03:34:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253039#M15772</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2015-12-04T03:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253040#M15773</link>
      <description>&lt;P&gt;use two pannels on a dashboard even for simply doing.&lt;BR /&gt;
install  &lt;STRONG&gt;Splunk 6.x Dashboard Examples&lt;/STRONG&gt; apps it is help you very fine to do it&lt;BR /&gt;
as several example thereof is inside, following this link  &lt;A href="https://splunkbase.splunk.com/app/1603/"&gt;https://splunkbase.splunk.com/app/1603/&lt;/A&gt;  to download &lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 09:30:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253040#M15773</guid>
      <dc:creator>forkingforwardt</dc:creator>
      <dc:date>2015-12-04T09:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253041#M15774</link>
      <description>&lt;P&gt;use two pannels on a dashboard even for simply doing.&lt;BR /&gt;
install  &lt;STRONG&gt;Splunk 6.x Dashboard Examples&lt;/STRONG&gt; apps it is help you very fine to do it&lt;BR /&gt;
as several example thereof is inside, following this link  &lt;A href="https://splunkbase.splunk.com/app/1603/"&gt;https://splunkbase.splunk.com/app/1603/&lt;/A&gt;  to download &lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 09:35:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253041#M15774</guid>
      <dc:creator>fdi01</dc:creator>
      <dc:date>2015-12-04T09:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253042#M15775</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have made something like this within my xml code in which my first query refers to target per_host_kpi's dashboard and another query refers the target to another host overview dashboard but the issue is it is giving output for first dashboard. When I clicked on the main screen overview it takes me to the per host kpi's dashboard but when i clicked on second  its not taking me to the another dashboard so any idea for this?&lt;/P&gt;

&lt;P&gt;Dynamic Drilldown&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=sc-perfmon (collection=cputime counter="% User Time") OR (collection=Memory counter="% Committed Bytes In Use") | stats sparkline(avg(Value)) as "Load trend", latest(_time) as latest_event, latest(eval(round(Value, 2))) as "Latest value" by host,collection |eval "Seconds since latest event"=floor((now() -latest_event)) | eval "Host metric"=case(collection == "CPUTime", "CPU time user %", collection == "Memory", "Memory in use %") | table host, "Host metric", "Latest value", "Load trend", "Seconds since latest event"&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;-7d@h&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;drilldown&amp;gt;
      &amp;lt;link target="_blank"&amp;gt;http://10.0.xx.xx:xx/en-US/app/sc_monitoring/per_host_kpis?form.src_type_tok=$row.sourcetype$&amp;lt;/link&amp;gt;
    &amp;lt;/drilldown&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=sc-perfmon collection=FreeDiskSpace counter="% Free Space" NOT(instance=_Total) |chart max(eval(ceiling(100-Value))) as disk_in_use over host by instance&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;-7d@h&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;drilldown&amp;gt;
      &amp;lt;link target="_blank"&amp;gt;http://10.0.xx.xx:xx/en-US/app/sc_monitoring/host_overview?form.src_type_tok=$row.sourcetype$&amp;lt;/link&amp;gt;
    &amp;lt;/drilldown&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
  &amp;lt;/table&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:04:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253042#M15775</guid>
      <dc:creator>sunnyparmar</dc:creator>
      <dc:date>2020-09-29T08:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253043#M15776</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have made something like this within my xml code in which my first query refers to target per_host_kpi's dashboard and another query refers the target to another host overview dashboard but the issue is it is giving output for first dashboard. When I clicked on the main screen overview it takes me to the per host kpi's dashboard but when i clicked on second  its not taking me to the another dashboard so any idea for this?&lt;/P&gt;

&lt;P&gt;Dynamic Drilldown&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=sc-perfmon (collection=cputime counter="% User Time") OR (collection=Memory counter="% Committed Bytes In Use") | stats sparkline(avg(Value)) as "Load trend", latest(_time) as latest_event, latest(eval(round(Value, 2))) as "Latest value" by host,collection |eval "Seconds since latest event"=floor((now() -latest_event)) | eval "Host metric"=case(collection == "CPUTime", "CPU time user %", collection == "Memory", "Memory in use %") | table host, "Host metric", "Latest value", "Load trend", "Seconds since latest event"&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;-7d@h&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;drilldown&amp;gt;
      &amp;lt;link target="_blank"&amp;gt;http://10.0.xx.xx:xx/en-US/app/sc_monitoring/per_host_kpis?form.src_type_tok=$row.sourcetype$&amp;lt;/link&amp;gt;
    &amp;lt;/drilldown&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=sc-perfmon collection=FreeDiskSpace counter="% Free Space" NOT(instance=_Total) |chart max(eval(ceiling(100-Value))) as disk_in_use over host by instance&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;-7d@h&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;drilldown&amp;gt;
      &amp;lt;link target="_blank"&amp;gt;http://10.0.xx.xx:xx/en-US/app/sc_monitoring/host_overview?form.src_type_tok=$row.sourcetype$&amp;lt;/link&amp;gt;
    &amp;lt;/drilldown&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
  &amp;lt;/table&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:04:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253043#M15776</guid>
      <dc:creator>sunnyparmar</dc:creator>
      <dc:date>2020-09-29T08:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253044#M15777</link>
      <description>&lt;P&gt;From your example, you are trying to do drill down in same panel on same table unless you haven't pasted complete code. You can have only one drill down per table as far as I know. &lt;/P&gt;

&lt;P&gt;If its a second table, please make sure that you have a page &lt;STRONG&gt;host_overview&lt;/STRONG&gt; and it's using a token &lt;STRONG&gt;src_type_tok&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;Interestingly, there is no sourcetype field in any of your searches (probably complete xml is not pasted here)&lt;/P&gt;

&lt;P&gt;So , there should be a page &lt;EM&gt;per_host_kpis&lt;/EM&gt; and should have a &lt;EM&gt;src_type_tok&lt;/EM&gt; token and there should be another page &lt;EM&gt;host_overview&lt;/EM&gt; also with &lt;EM&gt;src_type_tok&lt;/EM&gt; token &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:08:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253044#M15777</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-09-29T08:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253045#M15778</link>
      <description>&lt;P&gt;thanks for the answer but still not able to get it clear.. could you have some code that you have implemented on your side so can you share it please?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 09:19:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253045#M15778</guid>
      <dc:creator>sunnyparmar</dc:creator>
      <dc:date>2015-12-08T09:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253046#M15779</link>
      <description>&lt;P&gt;From the first dashboard(source) , I take sourcetype from the table and pass it to target dashboard.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    &amp;lt;dashboard&amp;gt;
      &amp;lt;label&amp;gt;Source &amp;lt;/label&amp;gt;
      &amp;lt;row&amp;gt;
        &amp;lt;panel&amp;gt;
          &amp;lt;table&amp;gt;
            &amp;lt;title&amp;gt;Sourcetypes&amp;lt;/title&amp;gt;
            &amp;lt;search&amp;gt;
              &amp;lt;query&amp;gt;index=*|stats count by sourcetype&amp;lt;/query&amp;gt;
              &amp;lt;earliest&amp;gt;-15m&amp;lt;/earliest&amp;gt;
              &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
            &amp;lt;/search&amp;gt;
            &amp;lt;option name="wrap"&amp;gt;undefined&amp;lt;/option&amp;gt;
            &amp;lt;option name="rowNumbers"&amp;gt;undefined&amp;lt;/option&amp;gt;
            &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
            &amp;lt;drilldown&amp;gt;
              **&amp;lt;link&amp;gt;/app/search/target?form.sourcetype=$row.sourcetype$&amp;lt;/link&amp;gt;**
            &amp;lt;/drilldown&amp;gt;
          &amp;lt;/table&amp;gt;
        &amp;lt;/panel&amp;gt;
      &amp;lt;/row&amp;gt;
    &amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In the target dashboard I am using the token in my search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;Target&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;title&amp;gt;Details&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=* sourcetype=**$form.sourcetype$**&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-15m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;undefined&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;undefined&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And from target I can drilldown to another page, and so on. If you want to call back the source page from target, make sure that in the source dashboard, you are using the token which is passed from target.&lt;/P&gt;

&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 09:46:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253046#M15779</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2015-12-08T09:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253047#M15780</link>
      <description>&lt;P&gt;thanks for the sharing.. I have used your first dashboard (source) like in given below format but it is giving error no result found. Could you tell me please where i am wrong&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   &amp;lt;label&amp;gt;host_kpi's &amp;lt;/label&amp;gt;
   &amp;lt;row&amp;gt;
     &amp;lt;panel&amp;gt;
       &amp;lt;table&amp;gt;
         &amp;lt;title&amp;gt;Perfmon:CPUTime &amp;lt;/title&amp;gt;
         &amp;lt;search&amp;gt;
           &amp;lt;query&amp;gt;index=sc-perfmon|stats count by Perfmon:CPUTime &amp;lt;/query&amp;gt;
           &amp;lt;earliest&amp;gt;-15m&amp;lt;/earliest&amp;gt;
           &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
         &amp;lt;/search&amp;gt;
         &amp;lt;option name="wrap"&amp;gt;undefined&amp;lt;/option&amp;gt;
         &amp;lt;option name="rowNumbers"&amp;gt;undefined&amp;lt;/option&amp;gt;
         &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
         &amp;lt;drilldown&amp;gt;
           **&amp;lt;link&amp;gt;/app/search/target?form.sourcetype=$row.sourcetype$&amp;lt;/link&amp;gt;**
         &amp;lt;/drilldown&amp;gt;
       &amp;lt;/table&amp;gt;
     &amp;lt;/panel&amp;gt;
   &amp;lt;/row&amp;gt;
 &amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 08 Dec 2015 10:45:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253047#M15780</guid>
      <dc:creator>sunnyparmar</dc:creator>
      <dc:date>2015-12-08T10:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253048#M15781</link>
      <description>&lt;P&gt;The ** around link is badly formatted bold. Please remove that and only use&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;          &amp;lt;drilldown&amp;gt;
            &amp;lt;link&amp;gt;/app/search/target?form.sourcetype=$row.sourcetype$&amp;lt;/link&amp;gt;
          &amp;lt;/drilldown&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 08 Dec 2015 10:49:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253048#M15781</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2015-12-08T10:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253049#M15782</link>
      <description>&lt;P&gt;still no result found..&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 10:53:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253049#M15782</guid>
      <dc:creator>sunnyparmar</dc:creator>
      <dc:date>2015-12-08T10:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253050#M15783</link>
      <description>&lt;P&gt;The result not found is due to lack of events. Do you have some events for below search.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=sc-perfmon earliest=-15m|stats count by Perfmon:CPUTime
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also does it have sourcetype column in the table. By $row.sourcetype$ we are picking up the sourcetype column from the row you clicked for  drilldown&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 10:56:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253050#M15783</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2015-12-08T10:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253051#M15784</link>
      <description>&lt;P&gt;no.. don't get any result for the query.. so what to do in this case? Please suggest.. thanks&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 10:58:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253051#M15784</guid>
      <dc:creator>sunnyparmar</dc:creator>
      <dc:date>2015-12-08T10:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253052#M15785</link>
      <description>&lt;P&gt;no.. don't get any result for the query.. so what to do in this case? Please suggest.. thanks&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 10:58:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253052#M15785</guid>
      <dc:creator>sunnyparmar</dc:creator>
      <dc:date>2015-12-08T10:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253053#M15786</link>
      <description>&lt;P&gt;So if you don't have a result, we can not do anything unless you push some data &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;In between do you have some results for index=sc-perfmon earliest=-15m ? or increase the time window.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 11:01:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253053#M15786</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2015-12-08T11:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253054#M15787</link>
      <description>&lt;P&gt;answer for your question - does it have sourcetype column in the table. By $row.sourcetype$ we are picking up the sourcetype column from the row you clicked for drilldown&lt;/P&gt;

&lt;P&gt;No&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 11:01:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253054#M15787</guid>
      <dc:creator>sunnyparmar</dc:creator>
      <dc:date>2015-12-08T11:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253055#M15788</link>
      <description>&lt;P&gt;yes.. i am getting data for this much query (index=sc-perfmon earliest=-15m )&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 11:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253055#M15788</guid>
      <dc:creator>sunnyparmar</dc:creator>
      <dc:date>2015-12-08T11:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253056#M15789</link>
      <description>&lt;P&gt;I have tried this query (index=sc-perfmon earliest=-15m|stats count by Perfmon:CPUTime&lt;BR /&gt;
) on my production server as well but there also i didn't get any data.. actually previously i was running query on Splunk test server .. but on production also it is not giving any data with this query &lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 11:10:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253056#M15789</guid>
      <dc:creator>sunnyparmar</dc:creator>
      <dc:date>2015-12-08T11:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: how to link two dashboards in splunk 6.2</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253057#M15790</link>
      <description>&lt;P&gt;To drill down from a table , the table should have the field name to pass as the token.&lt;/P&gt;

&lt;P&gt;From your original dashboard, i took host as drilldown token since host is part of result set&lt;/P&gt;

&lt;P&gt;Dashboard 1&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;      &amp;lt;dashboard&amp;gt;
       &amp;lt;label&amp;gt;Source&amp;lt;/label&amp;gt;
       &amp;lt;row&amp;gt;
         &amp;lt;panel&amp;gt;
           &amp;lt;table&amp;gt;
             &amp;lt;title&amp;gt;&amp;lt;/title&amp;gt;
             &amp;lt;search&amp;gt;
               &amp;lt;query&amp;gt;index=sc-perfmon (collection=cputime counter="% User Time") OR (collection=Memory counter="% Committed Bytes In Use") | stats sparkline(avg(Value)) as "Load trend", latest(_time) as latest_event, latest(eval(round(Value, 2))) as "Latest value" by host,collection |eval "Seconds since latest event"=floor((now() -latest_event)) | eval "Host metric"=case(collection == "CPUTime", "CPU time user %", collection == "Memory", "Memory in use %") | table host, "Host metric", "Latest value", "Load trend", "Seconds since latest event"&amp;lt;/query&amp;gt;
               &amp;lt;earliest&amp;gt;-7d@h&amp;lt;/earliest&amp;gt;
               &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
             &amp;lt;/search&amp;gt;
             &amp;lt;option name="wrap"&amp;gt;undefined&amp;lt;/option&amp;gt;
             &amp;lt;option name="rowNumbers"&amp;gt;undefined&amp;lt;/option&amp;gt;
             &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
             &amp;lt;drilldown&amp;gt;
                &amp;lt;link&amp;gt;http://10.0.xx.xx:xx/en-US/app/sc_monitoring/per_host_kpis?form.host=$row.host$&amp;lt;/link&amp;gt;
             &amp;lt;/drilldown&amp;gt;
           &amp;lt;/table&amp;gt;
         &amp;lt;/panel&amp;gt;
       &amp;lt;/row&amp;gt;
     &amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Dashboard 2&lt;/P&gt;

&lt;P&gt;I used the host which is passed from source to filter the result in search query&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;     &amp;lt;dashboard&amp;gt;
       &amp;lt;label&amp;gt;Target&amp;lt;/label&amp;gt;
       &amp;lt;row&amp;gt;
         &amp;lt;panel&amp;gt;
           &amp;lt;table&amp;gt;
             &amp;lt;title&amp;gt;&amp;lt;/title&amp;gt;
             &amp;lt;search&amp;gt;
               &amp;lt;query&amp;gt;index=sc-perfmon collection=FreeDiskSpace counter="% Free Space" NOT(instance=_Total) host=$form.host$ |chart max(eval(ceiling(100-Value))) as disk_in_use over host by instance&amp;lt;/query&amp;gt;
               &amp;lt;earliest&amp;gt;-7d@h&amp;lt;/earliest&amp;gt;
               &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
             &amp;lt;/search&amp;gt;
             &amp;lt;option name="wrap"&amp;gt;undefined&amp;lt;/option&amp;gt;
             &amp;lt;option name="rowNumbers"&amp;gt;undefined&amp;lt;/option&amp;gt;
             &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
           &amp;lt;/table&amp;gt;
         &amp;lt;/panel&amp;gt;
       &amp;lt;/row&amp;gt;
     &amp;lt;/dashboard&amp;gt;  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You have to now look at your data and fine tune according to your requirement.&lt;/P&gt;

&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 11:16:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-link-two-dashboards-in-splunk-6-2/m-p/253057#M15790</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2015-12-08T11:16:13Z</dc:date>
    </item>
  </channel>
</rss>

