<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Direct HTML drilldown breaks %-character encoding on click? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Direct-HTML-drilldown-breaks-character-encoding-on-click/m-p/475538#M31233</link>
    <description>&lt;P&gt;This is a possible solution. I have not tried it yet&lt;/P&gt;

&lt;P&gt;Gregg Woodcock:church:  6:13 PM&lt;BR /&gt;
Did you try the filters like |u and |n and |s?&lt;/P&gt;

&lt;P&gt;Nick  4:09 PM&lt;BR /&gt;
no, mind explaining further @Gregg Woodcock?&lt;/P&gt;

&lt;P&gt;Gareth Anderson  5:24 PM&lt;BR /&gt;
Token filters&lt;BR /&gt;
Token filters ensure that you correctly capture the value of a token.&lt;BR /&gt;
FilterDescriptionWrap value in quotes&lt;BR /&gt;
$token_name|s$Ensures that quotation marks surround the value referenced by the token. Escapes all quotation characters, ", within the quoted value.HTML format&lt;BR /&gt;
$token_name|h$Ensures that the token value is valid for HTML formatting.&lt;BR /&gt;
Token values for the  element use this filter by default.&lt;BR /&gt;
URL format&lt;BR /&gt;
$token_name|u$Ensures that the token value is valid to use as a URL.&lt;BR /&gt;
Token values for the  element use this filter by default.&lt;BR /&gt;
Specify no character escaping&lt;BR /&gt;
$token_name|n$Prevents the default token filter from running. No characters in the token are escaped.&lt;BR /&gt;
5:24&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Viz/tokens" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Viz/tokens&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 05:06:41 GMT</pubDate>
    <dc:creator>nick405060</dc:creator>
    <dc:date>2020-09-30T05:06:41Z</dc:date>
    <item>
      <title>Direct HTML drilldown breaks %-character encoding on click?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Direct-HTML-drilldown-breaks-character-encoding-on-click/m-p/475536#M31231</link>
      <description>&lt;P&gt;I would like to drilldown. If I use the drilldown editor and set to &lt;CODE&gt;auto&lt;/CODE&gt;, this works, but this is unacceptable because we need the link to open in a new tab. So I tried setting the drilldown editor to custom, which I've done a thousand times before &lt;EM&gt;including&lt;/EM&gt; with other drilldowns on the dashboard I am having problems with. However for one specific drilldown, the custom drilldown made it so only a blank search would open in the new tab. In response I followed &lt;A href="https://answers.splunk.com/answers/621427/custom-drilldown-search-not-working.html" target="_blank"&gt;https://answers.splunk.com/answers/621427/custom-drilldown-search-not-working.html&lt;/A&gt; and coded the non-tokenized precise HTML link directly into my SimpleXML.&lt;/P&gt;
&lt;P&gt;However the encoding of the &lt;CODE&gt;%&lt;/CODE&gt; character breaks on click. Literally if I copy and paste the drilldown HTML code from SimpleXML into my browser, it works, but not if I click to drilldown. Splunk Answer #621427 deals with the drilldown editor breaking %-character encoding, but this is a HTML drilldown breaking %-character encoding.&lt;/P&gt;
&lt;P&gt;Any assistance?&lt;/P&gt;
&lt;P&gt;SimpleXML: &lt;CODE&gt;&amp;lt;base search&amp;gt; | where NOT duo_status="Active" | stats count(eval(isnull(mobile))) as nonairwatch_duo_inactive&lt;/CODE&gt; &lt;STRONG&gt;custom drilldown works&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;SimpleXML: &lt;CODE&gt;&amp;lt;base search&amp;gt; | eval last_vpn_access=strptime(last_vpn_access,"%Y-%m-%d %H:%M:%S")&lt;/CODE&gt; &lt;STRONG&gt;custom drilldown breaks&lt;/STRONG&gt;&lt;BR /&gt;SimpleXML drilldown HTML link: &lt;CODE&gt;... %20%7C%20eval%20last_vpn_access=strptime(last_vpn_access,%22%25Y-%25m-%25d%20%25H:%25M:%25S%22)&lt;/CODE&gt; &lt;STRONG&gt;correct syntax&lt;/STRONG&gt;&lt;BR /&gt;Browser URL when clicked: &lt;CODE&gt;https:// ... %20|%20eval%20last_vpn_access=strptime(last_vpn_access,"%Y-%m-%d%20%H:%M:%S")&lt;/CODE&gt; &lt;STRONG&gt;incorrect syntax&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 00:00:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Direct-HTML-drilldown-breaks-character-encoding-on-click/m-p/475536#M31231</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2020-06-08T00:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Direct HTML drilldown breaks %-character encoding on click?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Direct-HTML-drilldown-breaks-character-encoding-on-click/m-p/475537#M31232</link>
      <description>&lt;P&gt;@nick405060 &lt;/P&gt;

&lt;P&gt;Can you please share your sample code?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 05:44:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Direct-HTML-drilldown-breaks-character-encoding-on-click/m-p/475537#M31232</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2020-04-14T05:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: Direct HTML drilldown breaks %-character encoding on click?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Direct-HTML-drilldown-breaks-character-encoding-on-click/m-p/475538#M31233</link>
      <description>&lt;P&gt;This is a possible solution. I have not tried it yet&lt;/P&gt;

&lt;P&gt;Gregg Woodcock:church:  6:13 PM&lt;BR /&gt;
Did you try the filters like |u and |n and |s?&lt;/P&gt;

&lt;P&gt;Nick  4:09 PM&lt;BR /&gt;
no, mind explaining further @Gregg Woodcock?&lt;/P&gt;

&lt;P&gt;Gareth Anderson  5:24 PM&lt;BR /&gt;
Token filters&lt;BR /&gt;
Token filters ensure that you correctly capture the value of a token.&lt;BR /&gt;
FilterDescriptionWrap value in quotes&lt;BR /&gt;
$token_name|s$Ensures that quotation marks surround the value referenced by the token. Escapes all quotation characters, ", within the quoted value.HTML format&lt;BR /&gt;
$token_name|h$Ensures that the token value is valid for HTML formatting.&lt;BR /&gt;
Token values for the  element use this filter by default.&lt;BR /&gt;
URL format&lt;BR /&gt;
$token_name|u$Ensures that the token value is valid to use as a URL.&lt;BR /&gt;
Token values for the  element use this filter by default.&lt;BR /&gt;
Specify no character escaping&lt;BR /&gt;
$token_name|n$Prevents the default token filter from running. No characters in the token are escaped.&lt;BR /&gt;
5:24&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Viz/tokens" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Viz/tokens&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:06:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Direct-HTML-drilldown-breaks-character-encoding-on-click/m-p/475538#M31233</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2020-09-30T05:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Direct HTML drilldown breaks %-character encoding on click?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Direct-HTML-drilldown-breaks-character-encoding-on-click/m-p/475539#M31234</link>
      <description>&lt;P&gt;In addition, Splunk fails to encode ? in 7.2.0 HTML IN the SimpleXML HTML drilldown link. It leaves it as ? and does not properly encode the %3F. There are many other HTML encoding issues in 7.2.0 HTML e.g. it will randomly insert "%0A" and break the drilldown&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 22:06:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Direct-HTML-drilldown-breaks-character-encoding-on-click/m-p/475539#M31234</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2020-05-20T22:06:53Z</dc:date>
    </item>
  </channel>
</rss>

