<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &amp;gt; 0 in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556460#M158039</link>
    <description>&lt;P&gt;Yes&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235223"&gt;@Luciana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can define multiple tokens and use it. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Jun 2021 05:32:53 GMT</pubDate>
    <dc:creator>kamlesh_vaghela</dc:creator>
    <dc:date>2021-06-21T05:32:53Z</dc:date>
    <item>
      <title>Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/554983#M157516</link>
      <description>&lt;P&gt;Guys,&amp;nbsp; I've created a dashboard where I hunt IOCs from OTX intelligence across several logs in Splunk.&lt;/P&gt;&lt;P&gt;This dashboard initially was created to show is some IOC was found, and once we click in the number (stats count command) , then the drilldown executes a second query giving us more information (|table command)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Luciana_0-1623191632295.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14547i2095742922FFA92F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Luciana_0-1623191632295.png" alt="Luciana_0-1623191632295.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, besides that, I want the dashboard send us an email in case the count &amp;gt;0 every time, then I used sendemail, however, I cant use the sendemail command where the stats count command is because I will receive an email only with the number &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;so, I thought about using the sendemail in the second query, however, it only will send the email if one of us CLICK in the number , so, I was trying to find a way to turn the drilldown more automatic, which means, once the result &amp;gt;0, automatically the drilldown would be activated without clicking.&lt;/P&gt;&lt;P&gt;I am wonder if this is possible , or if there is other solution that I can use without giving up the design of the dashboard?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below the dashboard source:&amp;nbsp;&lt;/P&gt;&lt;P&gt;(pay attention to the lookup that I am doing for domain)&lt;/P&gt;&lt;P&gt;&amp;lt;form theme="dark"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;label&amp;gt;_My company_IOC hits by OTX&amp;lt;/label&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;description&amp;gt;(proxy, Firewalls, load balancers)&amp;lt;/description&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;fieldset submitButton="true"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;input type="time" token="time"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;label&amp;gt;Time Range&amp;lt;/label&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;default&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;earliest&amp;gt;-4h@m&amp;lt;/earliest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/default&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/input&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;input type="text" searchWhenChanged="true" token="wild"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;label&amp;gt;Wildcard Search&amp;lt;/label&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/input&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;/fieldset&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;row&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;panel&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;title&amp;gt;My Tool&amp;lt;/title&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;single&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;title&amp;gt;Hits by URL&amp;lt;/title&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;search&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;query&amp;gt;index = XXX_XXX_My Tool_proxy_all_01 sourcetype=My Toolnss-web action=Allowed [|inputlookup OTX | search type=URL | rename indicator as url | table url] |dedup user |stats count&amp;lt;/query&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;earliest&amp;gt;$time.earliest$&amp;lt;/earliest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;latest&amp;gt;$time.latest$&amp;lt;/latest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;refresh&amp;gt;300s&amp;lt;/refresh&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/search&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="colorMode"&amp;gt;block&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="drilldown"&amp;gt;all&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="rangeColors"&amp;gt;["0x65a637","0xd93f3c"]&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="rangeValues"&amp;gt;[0]&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="underLabel"&amp;gt;URL&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;drilldown&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;set token="alert"&amp;gt;index = XXX_XXX_My Tool_proxy_all_01 sourcetype=My Toolnss-web action=Allowed [|inputlookup OTX | search type=URL | rename indicator as url | table url] | dedup user | table _time, url, user, src, serverip, ClientIP&amp;lt;/set&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/drilldown&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/single&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/panel&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;panel&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;title&amp;gt;My Tool&amp;lt;/title&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;single&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;title&amp;gt;Hits by Domain/Hostname&amp;lt;/title&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;search&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;query&amp;gt;index = XXX_XXX_My Tool_proxy_all_01 sourcetype=My Toolnss-web action=Allowed [|inputlookup OTX | search type=domain OR type=hostname | rename indicator as hostname | table hostname] |dedup user |stats count&amp;lt;/query&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;earliest&amp;gt;$time.earliest$&amp;lt;/earliest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;latest&amp;gt;$time.latest$&amp;lt;/latest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;refresh&amp;gt;200s&amp;lt;/refresh&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/search&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="colorMode"&amp;gt;block&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="drilldown"&amp;gt;all&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="rangeColors"&amp;gt;["0x65a637","0xd93f3c"]&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="rangeValues"&amp;gt;[0]&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="underLabel"&amp;gt;URL&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;drilldown&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;set token="alert"&amp;gt;index = XXX_XXX_My Tool_proxy_all_01 sourcetype=My Toolnss-web action=Allowed [|inputlookup OTX | search type=domain OR type=hostname | rename indicator as hostname | table hostname] |dedup user | table _time, hostname, domain, user, serverip, ClientIP |sendemail to="myaddress@mydomamin.com" server=smtp.server.co.nz subject="OTX - My Tool Notification - IOC found by Domain" message="This is an test message" sendresults=true inline=true format=csv&amp;lt;/set&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/drilldown&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really appreciate any help or idea. thanks Luciana&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 23:12:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/554983#M157516</guid>
      <dc:creator>Luciana</dc:creator>
      <dc:date>2021-06-08T23:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/554996#M157518</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235223"&gt;@Luciana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you tried this in drilldown?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;drilldown&amp;gt;
            &amp;lt;condition match="'click.value'!= 0"&amp;gt;
               &amp;lt;set token="alert"&amp;gt; MY SEARCH&amp;lt;/set&amp;gt;
            &amp;lt;/condition&amp;gt;
            &amp;lt;condition&amp;gt;
              &amp;lt;unset token="alert"&amp;gt;&amp;lt;/unset&amp;gt;
            &amp;lt;/condition&amp;gt;
        &amp;lt;/drilldown&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 05:47:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/554996#M157518</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-10T05:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/555197#M157588</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for replying me. so, I tried this, but I continue with the same problem which is that I have to CLICK in the number , in order to show me the details inside the 'Information Table' in the bottom.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd like the results would go there WITHOUT clicking if the count&amp;nbsp;!= 0&lt;/P&gt;&lt;P&gt;IF I add this condition here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Luciana_0-1623278474841.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14563i68E5DFC9E8CD2746/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Luciana_0-1623278474841.png" alt="Luciana_0-1623278474841.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Besides I have to CLICK in the number to the results show up in the "information table' , what happened is when I click the SEARCH window opens to me &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 22:44:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/555197#M157588</guid>
      <dc:creator>Luciana</dc:creator>
      <dc:date>2021-06-09T22:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/555225#M157599</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235223"&gt;@Luciana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this sample example ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;Single Value Test&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Single Value&amp;lt;/title&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;title&amp;gt;Single Value&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;done&amp;gt;
            &amp;lt;condition match="'result.count'!= &amp;amp;quot;0&amp;amp;quot;"&amp;gt;
              &amp;lt;set token="alert"&amp;gt;| makeresults | eval msg="Hello"&amp;lt;/set&amp;gt;
            &amp;lt;/condition&amp;gt;
            &amp;lt;condition&amp;gt;
              &amp;lt;unset token="alert"&amp;gt;&amp;lt;/unset&amp;gt;
            &amp;lt;/condition&amp;gt;
          &amp;lt;/done&amp;gt;
          &amp;lt;query&amp;gt;| makeresults | eval count=0 | table count&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;html&amp;gt;
        alert = $alert$
      &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;$alert$&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 05:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/555225#M157599</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-10T05:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/555412#M157661</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&amp;nbsp;, thanks for helping me!&lt;/P&gt;&lt;P&gt;so,&amp;nbsp;&lt;/P&gt;&lt;P&gt;you mean this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Luciana_0-1623377838041.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14589iF02FAB5DACF8E850/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Luciana_0-1623377838041.png" alt="Luciana_0-1623377838041.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 02:17:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/555412#M157661</guid>
      <dc:creator>Luciana</dc:creator>
      <dc:date>2021-06-11T02:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/555441#M157665</link>
      <description>&lt;P&gt;Yes&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235223"&gt;@Luciana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is sample dashboard. &amp;nbsp;You can use the same login in your dashboard. Please let us know if you found any difficulties &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 06:59:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/555441#M157665</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-11T06:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/555602#M157730</link>
      <description>Good Morning &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt; Sorry, I didnt understand the idea. Why Have you sent me this sample dashboard? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Do you want that I fill out all queries from my old dashboard to this one?</description>
      <pubDate>Sun, 13 Jun 2021 21:44:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/555602#M157730</guid>
      <dc:creator>Luciana</dc:creator>
      <dc:date>2021-06-13T21:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556263#M157956</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939" target="_blank"&gt;@kamlesh_vaghela&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;, How are you?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;look, I am considering that I cant do what I want because drilldown always will be requiring that user clicks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but actually , what I want is IF the search stats count &amp;gt;=1 then, a second search would be trigger and then, in this search I could use the sendemail command to send me alert with more information&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;so, considering&amp;nbsp; first query:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index = xxx sourcetype=xxx action=Allowed [|inputlookup OTX | search type=URL | rename indicator as url | table url] |dedup user |stats count&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;lt;condition match="$result.resultCount$&amp;gt;1"&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;then run a&amp;nbsp;second query:&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index = xxx sourcetype=xxx action=Allowed [|inputlookup OTX | search type=domain OR type=hostname | rename indicator as hostname | table hostname]&lt;BR /&gt;|dedup user |table _time, hostname, domain, user, serverip, ClientIP |sendemail to="myemail.co.nz" server=smtp.server.co.nz subject="Notification - IOC found by url" message="This is an test message" sendresults=true inline=true format=csv&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you know if is possible, or How Can I do this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I thought about set a token with&amp;nbsp;&lt;BR /&gt;&amp;lt;condition match="$result.resultCount$&amp;gt;1"&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;but then , I dont know how to trigger a second search if the condition is true&lt;/FONT&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you so much&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2021 02:30:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556263#M157956</guid>
      <dc:creator>Luciana</dc:creator>
      <dc:date>2021-06-18T02:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556265#M157957</link>
      <description>&lt;P&gt;or in another words...&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How to trigger second search based on first search where condition is : first result count &amp;gt;=1&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2021 02:37:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556265#M157957</guid>
      <dc:creator>Luciana</dc:creator>
      <dc:date>2021-06-18T02:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556271#M157961</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235223"&gt;@Luciana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By setting and unsetting token, you can trigger search to execute it.&lt;/P&gt;&lt;P&gt;Check below example, Here tkn_second_search is set when first search have some count. Please try this XML and let me know if any issue.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;Single Value Test&amp;lt;/label&amp;gt;
  &amp;lt;search id="first_search"&amp;gt;
    &amp;lt;query&amp;gt;index = xxx sourcetype=xxx action=Allowed [|inputlookup OTX | search type=URL | rename indicator as url | table url] |dedup user |stats count
    &amp;lt;/query&amp;gt;
    &amp;lt;done&amp;gt;
      &amp;lt;condition match="'result.count'!= &amp;amp;quot;0&amp;amp;quot;"&amp;gt;
        &amp;lt;set token="tkn_second_search"&amp;gt;
index = xxx sourcetype=xxx action=Allowed [|inputlookup OTX | search type=domain OR type=hostname | rename indicator as hostname | table hostname]
|dedup user |table _time, hostname, domain, user, serverip, ClientIP |sendemail to="myemail.co.nz" server=smtp.server.co.nz subject="Notification - IOC found by url" message="This is an test message" sendresults=true inline=true format=csv
        &amp;lt;/set&amp;gt;
      &amp;lt;/condition&amp;gt;
      &amp;lt;condition&amp;gt;
        &amp;lt;unset token="tkn_second_search"&amp;gt;&amp;lt;/unset&amp;gt;
      &amp;lt;/condition&amp;gt;
    &amp;lt;/done&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;html&amp;gt;
        Second Search Token = $tkn_second_search$
      &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;$tkn_second_search$&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Sample XML:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;Dependent Search Example&amp;lt;/label&amp;gt;
  &amp;lt;search id="first_search"&amp;gt;
    &amp;lt;query&amp;gt;| makeresults | eval count=1 | table count&amp;lt;/query&amp;gt;
    &amp;lt;done&amp;gt;
      &amp;lt;condition match="'result.count'!= &amp;amp;quot;0&amp;amp;quot;"&amp;gt;
        &amp;lt;set token="tkn_second_search"&amp;gt;| makeresults | eval msg="Hello"&amp;lt;/set&amp;gt;
      &amp;lt;/condition&amp;gt;
      &amp;lt;condition&amp;gt;
        &amp;lt;unset token="tkn_second_search"&amp;gt;&amp;lt;/unset&amp;gt;
      &amp;lt;/condition&amp;gt;
    &amp;lt;/done&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;html&amp;gt;
        Second Search Token = $tkn_second_search$
      &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;$tkn_second_search$&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2021 05:14:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556271#M157961</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-18T05:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556444#M158032</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&amp;nbsp; I hope you are having a good day! so, I've tried and it worked, now every time the first query has a result count &amp;gt; 0 the second search triggers and send an email &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I confirm with you if I understood&amp;nbsp; right the idea of: result.count'!= &amp;amp;quot;0&amp;amp;quot;"&lt;/P&gt;&lt;P&gt;( in case there are no results &amp;gt;=0, then it will show no results found?)&lt;/P&gt;&lt;P&gt;I thought about using the same logic for all queries in my dashboard, then, as for an example, I did a test in 3 queries , however in the query that we dont have any IOC is found (hits by URL - $tkn_first_search$) , it is appearing for me " search is waiting for input"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Luciana_0-1624249313164.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14701i1BC2DE337D510308/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Luciana_0-1624249313164.png" alt="Luciana_0-1624249313164.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;not sure is this is associated or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 04:24:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556444#M158032</guid>
      <dc:creator>Luciana</dc:creator>
      <dc:date>2021-06-21T04:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556452#M158036</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235223"&gt;@Luciana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below code is just for Debugging purpose. You can remove it.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;html&amp;gt;
        Second Search Token = $tkn_second_search$
      &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just use depends If you don't want to show panel with when token is not set. see below code.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;row&amp;gt;
    &amp;lt;panel depends="$tkn_second_search$"&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;$tkn_second_search$&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 05:14:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556452#M158036</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-21T05:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556454#M158037</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&amp;nbsp; thanks for all your help and I swear that is my last message&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've just changed the condition for : &amp;lt;condition match="'result.count'!= &amp;amp;quot;0No event for this table&amp;amp;quot;"&amp;gt; then it will show 'no results count. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;now, I am trying to add all my query results in ONE panel. I was checking your answer in the following&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-two-query-results-in-xml-dashboard/m-p/446539" target="_blank"&gt;https://community.splunk.com/t5/Dashboards-Visualizations/How-to-add-two-query-results-in-xml-dashboard/m-p/446539&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but,&amp;nbsp; I m not sure if I can use 2 different tokens (condition match that triggers my second query) and ($job.sid$) for the first query&lt;/P&gt;&lt;P&gt;Can you just confirm?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Luciana_1-1624252502754.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14702iE4EC9FBF812155BC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Luciana_1-1624252502754.png" alt="Luciana_1-1624252502754.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 05:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556454#M158037</guid>
      <dc:creator>Luciana</dc:creator>
      <dc:date>2021-06-21T05:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556460#M158039</link>
      <description>&lt;P&gt;Yes&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235223"&gt;@Luciana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can define multiple tokens and use it. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 05:32:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556460#M158039</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-21T05:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556462#M158040</link>
      <description>&lt;P&gt;ok&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&amp;nbsp; I will try to set different tokens. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Have you noticed that in the solution that you helped me has a little issue... once we set that token, the SECOND SEARCH will not run a second time if the FIRST SEARCH runs again? Do you know How Can I get this around?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for example, the stats count that was in RED changed to green, which means 0 IOCs found, but the bottom panel continues to show me the oldest result .&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 05:46:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556462#M158040</guid>
      <dc:creator>Luciana</dc:creator>
      <dc:date>2021-06-21T05:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556465#M158041</link>
      <description>&lt;P&gt;Yes&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235223"&gt;@Luciana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason!! My code on case of static values with No filters. But you can achieve this by adding below code on change of your filter,&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;        &amp;lt;unset token="tkn_second_search"&amp;gt;&amp;lt;/unset&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 05:53:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556465#M158041</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-21T05:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556467#M158043</link>
      <description>&lt;P&gt;but, I am doing it: check below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;search id="main_search1"&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index = my index sourcetype=my sourcetype action=Allowed [|inputlookup OTX | search type=URL | rename indicator as url | table url] |dedup user |stats count&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$time.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$time.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;refresh&amp;gt;3600s&amp;lt;/refresh&amp;gt;&lt;BR /&gt;&amp;lt;done&amp;gt;&lt;BR /&gt;&amp;lt;condition match="'result.count'!= &amp;amp;quot;0No event for this table&amp;amp;quot;"&amp;gt;&lt;BR /&gt;&amp;lt;set token="tkn_first_search"&amp;gt;index = my index sourcetype= my sourcetype action=Allowed [|inputlookup OTX | search type=URL | rename indicator as url | table url] |dedup user | table _time, url, user, serverip, ClientIP |sendemail to="myemail@domain.co.nz" server=smtp.server.co.nz subject="OTX -&amp;nbsp; Notification - IOC found by Domain" message="This is an test message" sendresults=true inline=true format=csv&amp;lt;/set&amp;gt;&lt;BR /&gt;&amp;lt;/condition&amp;gt;&lt;BR /&gt;&amp;lt;condition&amp;gt;&lt;BR /&gt;&amp;lt;unset token="tkn_first_search"&amp;gt;&amp;lt;/unset&amp;gt;&lt;BR /&gt;&amp;lt;/condition&amp;gt;&lt;BR /&gt;&amp;lt;/done&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 05:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556467#M158043</guid>
      <dc:creator>Luciana</dc:creator>
      <dc:date>2021-06-21T05:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556469#M158044</link>
      <description>&lt;P&gt;It should be with filters also..&lt;/P&gt;&lt;P&gt;Can you please share sample Filter code?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 06:00:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556469#M158044</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-21T06:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556593#M158077</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&amp;nbsp;, this is the whole code for 2 searches (URL and Domain stats count&amp;nbsp; and their respective panel that shows the second search ).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;title&amp;gt;Hits by URL&amp;lt;/title&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;search id="main_search1"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;query&amp;gt;index = xxx sourcetype=xxxx action=Allowed [|inputlookup OTX | search type=URL | rename indicator as url | table url] |dedup user |stats count&amp;lt;/query&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;earliest&amp;gt;$time.earliest$&amp;lt;/earliest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;latest&amp;gt;$time.latest$&amp;lt;/latest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;refresh&amp;gt;3600s&amp;lt;/refresh&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;done&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;condition match="'result.count'!= &amp;amp;quot;0No event for this table&amp;amp;quot;"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;set token="tkn_first_search"&amp;gt; index = xxx sourcetype=xxxx action=Allowed [|inputlookup OTX | search type=URL | rename indicator as url | table url] |dedup user | table _time, url, user, serverip, ClientIP |sendemail to="luciana.campos@Company.co.nz" server=smtp.Company.co.nz subject="OTX XXX Notification - IOC found by Domain" message="This is an test message" sendresults=true inline=true format=csv&amp;lt;/set&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/condition&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;condition&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;unset token="tkn_first_search"&amp;gt;&amp;lt;/unset&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/condition&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/done&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/search&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="colorMode"&amp;gt;block&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="rangeColors"&amp;gt;["0x65a637","0xd93f3c"]&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="rangeValues"&amp;gt;[0]&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="trellis.enabled"&amp;gt;0&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="underLabel"&amp;gt;Domainyrl&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/single&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/panel&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;panel&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;title&amp;gt;my title&amp;lt;/title&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;single&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;title&amp;gt;Hits by Domain_Hostname&amp;lt;/title&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;search id="main_search2"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;query&amp;gt;index = index = xxx sourcetype=xxxx action=Allowed [|inputlookup OTX | search type=domain OR type=hostname | rename indicator as hostname | table hostname] |dedup user |stats count&amp;lt;/query&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;earliest&amp;gt;$time.earliest$&amp;lt;/earliest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;latest&amp;gt;$time.latest$&amp;lt;/latest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;refresh&amp;gt;3600s&amp;lt;/refresh&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;done&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;condition match="'result.count'!= &amp;amp;quot;0No event for this table&amp;amp;quot;"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;set token="tkn_second_search"&amp;gt; index = xxx sourcetype=xxxx action=Allowed [|inputlookup OTX | search type=domain OR type=hostname | rename indicator as hostname | table hostname] |dedup user |table _time, hostname, domain, user, serverip, ClientIP |sendemail to="luciana.campos@Company.co.nz" server=smtp.Company.co.nz subject="OTX - XXX Notification - IOC found by Domain" message="This is an test message" sendresults=true inline=true format=csv&amp;lt;/set&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/condition&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;condition&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;unset token="tkn_second_search"&amp;gt;&amp;lt;/unset&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/condition&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/done&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/search&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="colorMode"&amp;gt;block&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="rangeColors"&amp;gt;["0x65a637","0xd93f3c"]&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="rangeValues"&amp;gt;[0]&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="trellis.enabled"&amp;gt;0&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="underLabel"&amp;gt;Domainyrl&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/single&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/panel&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;panel&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;title&amp;gt;Query 1&amp;lt;/title&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;table&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;search&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;query&amp;gt;$tkn_first_search$&amp;lt;/query&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;earliest&amp;gt;-4h@h&amp;lt;/earliest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/search&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/table&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/panel&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;/row&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;row&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;panel&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;title&amp;gt;Query2&amp;lt;/title&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;table&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;search&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;query&amp;gt;$tkn_second_search$&amp;lt;/query&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;earliest&amp;gt;-4h@h&amp;lt;/earliest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/search&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/table&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/panel&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;/row&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;row&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;panel&amp;gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 21 Jun 2021 23:36:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556593#M158077</guid>
      <dc:creator>Luciana</dc:creator>
      <dc:date>2021-06-21T23:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard using drilldown showing detailed info, but also sending email alert for us if result &gt; 0</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556611#M158082</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&amp;nbsp; let me know if you need something more, please? I dont have anything more in my dashboard than this.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 04:02:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-dashboard-using-drilldown-showing-detailed-info-but-also/m-p/556611#M158082</guid>
      <dc:creator>Luciana</dc:creator>
      <dc:date>2021-06-22T04:02:42Z</dc:date>
    </item>
  </channel>
</rss>

