<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create a drilldown in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471736#M132728</link>
    <description>&lt;P&gt;when i click on user count for example its taking user=4 . I want the value values instead of number.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Sep 2019 19:57:58 GMT</pubDate>
    <dc:creator>jsuryaprakash</dc:creator>
    <dc:date>2019-09-04T19:57:58Z</dc:date>
    <item>
      <title>How to create a drilldown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471734#M132726</link>
      <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;
I am trying to create a simple hiding drill down panel. &lt;BR /&gt;
With below search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal |stats dc(user) as uniqueusers by sourcetype host 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Which gives below table:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;sourcetype      host     uniqueusers&lt;BR /&gt;
aaaa                    ccc          4&lt;BR /&gt;
bbbbb                ddddd     2&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;When a user clicks on uniquesusers value for example 4 it should show a new panel below with list of 4 uniqueuser names.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 19:50:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471734#M132726</guid>
      <dc:creator>jsuryaprakash</dc:creator>
      <dc:date>2019-09-04T19:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a drilldown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471735#M132727</link>
      <description>&lt;P&gt;below is the query i achieved so far. i am unable to parse the token value&lt;/P&gt;

&lt;P&gt;DrillDown&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=_*|stats dc(user) as user  by sourcetype host source&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;-15m&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;drilldown&amp;gt;
      &amp;lt;set token="show_panel"&amp;gt;true&amp;lt;/set&amp;gt;
      &amp;lt;set token="selected_value"&amp;gt;$click.value2$&amp;lt;/set&amp;gt;
    &amp;lt;/drilldown&amp;gt;
  &amp;lt;/table&amp;gt;
&amp;lt;/panel&amp;gt;


&amp;lt;panel depends="$selected_value$"&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=_* |stats values(user) as user  by sourcetype host source | mvexpand user| search user=$selected_value$ &amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;-15m&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
    &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
  &amp;lt;/table&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 04 Sep 2019 19:57:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471735#M132727</guid>
      <dc:creator>jsuryaprakash</dc:creator>
      <dc:date>2019-09-04T19:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a drilldown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471736#M132728</link>
      <description>&lt;P&gt;when i click on user count for example its taking user=4 . I want the value values instead of number.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 19:57:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471736#M132728</guid>
      <dc:creator>jsuryaprakash</dc:creator>
      <dc:date>2019-09-04T19:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a drilldown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471737#M132729</link>
      <description>&lt;P&gt;Try this : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;test&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_*|stats dc(user) as user  by sourcetype host source&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-15m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;drilldown&amp;gt;
          &amp;lt;set token="show_panel"&amp;gt;true&amp;lt;/set&amp;gt;
          &amp;lt;set token="user"&amp;gt;$click.value2$&amp;lt;/set&amp;gt;
          &amp;lt;set token="source"&amp;gt;$row.source$&amp;lt;/set&amp;gt;
          &amp;lt;set token="host"&amp;gt;$row.host$&amp;lt;/set&amp;gt;
        &amp;lt;/drilldown&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel depends="$user$"&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_* |stats values(user) as user dc(user) as user_count  by sourcetype host source | search user_count=$user$ source="$source$" host=$host$ | mvexpand user&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-15m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 04 Sep 2019 21:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471737#M132729</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2019-09-04T21:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a drilldown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471738#M132730</link>
      <description>&lt;P&gt;It’s only working for the first value of the user column.&lt;BR /&gt;
For other values in that column it’s showing no data. Can you please look into it.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 03:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471738#M132730</guid>
      <dc:creator>jsuryaprakash</dc:creator>
      <dc:date>2019-09-05T03:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a drilldown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471739#M132731</link>
      <description>&lt;P&gt;It's working for me for each value of the user column. create a new dashboard and copy-paste entire XML.  &lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 15:04:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-drilldown/m-p/471739#M132731</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2019-09-05T15:04:31Z</dc:date>
    </item>
  </channel>
</rss>

