<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple Custom Dynamic Drilldowns in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Custom-Dynamic-Drilldowns/m-p/84819#M4585</link>
    <description>&lt;P&gt;Is it possible to have a customized drilldown result per link?  The idea is a form, which will initially result to displaying the different sourcetypes of the search, then per sourcetype result, I can drilldown to a simple table or a stats table that is created based on the sourcetype that is clicked on.&lt;/P&gt;

&lt;P&gt;For example, the form search returned 3 sourcetypes, firewall, URL filter and AV.  When I click on firewall, it will drill down to a table that shows fields related to the sourcetype (src,dst,port,etc.).  Same follows for the other results when clicked on,  URL filter (src,dst,URL,operation, argument,user-agent, etc.) and AV (sr,dst,signature,file,etc.)&lt;/P&gt;

&lt;P&gt;Hope this is possible and someone can share an idea.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Oct 2013 03:03:51 GMT</pubDate>
    <dc:creator>mcm10285</dc:creator>
    <dc:date>2013-10-07T03:03:51Z</dc:date>
    <item>
      <title>Multiple Custom Dynamic Drilldowns</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Custom-Dynamic-Drilldowns/m-p/84819#M4585</link>
      <description>&lt;P&gt;Is it possible to have a customized drilldown result per link?  The idea is a form, which will initially result to displaying the different sourcetypes of the search, then per sourcetype result, I can drilldown to a simple table or a stats table that is created based on the sourcetype that is clicked on.&lt;/P&gt;

&lt;P&gt;For example, the form search returned 3 sourcetypes, firewall, URL filter and AV.  When I click on firewall, it will drill down to a table that shows fields related to the sourcetype (src,dst,port,etc.).  Same follows for the other results when clicked on,  URL filter (src,dst,URL,operation, argument,user-agent, etc.) and AV (sr,dst,signature,file,etc.)&lt;/P&gt;

&lt;P&gt;Hope this is possible and someone can share an idea.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2013 03:03:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Custom-Dynamic-Drilldowns/m-p/84819#M4585</guid>
      <dc:creator>mcm10285</dc:creator>
      <dc:date>2013-10-07T03:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Custom Dynamic Drilldowns</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Custom-Dynamic-Drilldowns/m-p/84820#M4586</link>
      <description>&lt;P&gt;Yes this is possible, there are several different techniques that can be combined:&lt;/P&gt;

&lt;P&gt;First, custom drill down lets you specify a link to take per field/series clicked on: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0/Viz/Dynamicdrilldownindashboardsandforms"&gt;http://docs.splunk.com/Documentation/Splunk/6.0/Viz/Dynamicdrilldownindashboardsandforms&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Second, in page drill down in Simple XML in Splunk 6.0.  If you look at the &lt;A href="http://apps.splunk.com/app/1603" title="Splunk 6 Dashboard Examples"&gt;Splunk 6.0 Dashboard Examples&lt;/A&gt; (note: requires javascript knowledge)&lt;/P&gt;

&lt;P&gt;Lastly, use tokens to select a macro.  This allows you to specify different search snippets based on user input.  This is useful in either advanced xml or simple xml.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2013 22:59:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Custom-Dynamic-Drilldowns/m-p/84820#M4586</guid>
      <dc:creator>melting</dc:creator>
      <dc:date>2013-10-07T22:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Custom Dynamic Drilldowns</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Custom-Dynamic-Drilldowns/m-p/84821#M4587</link>
      <description>&lt;P&gt;First item cannot deliver the requirement.&lt;/P&gt;

&lt;P&gt;Second item not feasible at this time, I am at 5.0.3.&lt;/P&gt;

&lt;P&gt;"Lastly, use tokens to select a macro.  This allows you to specify different search snippets based on user input.  This is useful in either advanced xml or simple xml."&lt;/P&gt;

&lt;P&gt;--&amp;gt; Is this applicable to v5.0.3?  Also, would you have references that you can point me to?  Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2013 03:08:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Custom-Dynamic-Drilldowns/m-p/84821#M4587</guid>
      <dc:creator>mcm10285</dc:creator>
      <dc:date>2013-10-08T03:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Custom Dynamic Drilldowns</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Custom-Dynamic-Drilldowns/m-p/84822#M4588</link>
      <description>&lt;P&gt;I downvoted this post because link dead&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2016 07:37:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Multiple-Custom-Dynamic-Drilldowns/m-p/84822#M4588</guid>
      <dc:creator>muellernc</dc:creator>
      <dc:date>2016-06-27T07:37:24Z</dc:date>
    </item>
  </channel>
</rss>

