<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Drilldown on results of a subsearch not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295316#M160359</link>
    <description>&lt;P&gt;The code falls under the option name= and are as follows - wrap, rowNumbers, dataOverlayMode, list.drolldown,list.wrap, maxLines, raw.drilldown, table.drilldown, table.wrap, type, drilldown, and count with the answer to those options listed above.&lt;/P&gt;

&lt;P&gt;TY&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jul 2017 00:31:41 GMT</pubDate>
    <dc:creator>doogan12</dc:creator>
    <dc:date>2017-07-05T00:31:41Z</dc:date>
    <item>
      <title>Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295312#M160355</link>
      <description>&lt;P&gt;Woodcock - As a new question to the previous one that you help resolve - do you have any idea why the drilldown isn't working? When I click on the results that the search produced, it shows and runs the search string of the original search instead of the results of the search - just like clicking the magnifying glass icon does. In the source code, drilldown is set to cell. Any thoughts?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2017 23:14:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295312#M160355</guid>
      <dc:creator>doogan12</dc:creator>
      <dc:date>2017-07-04T23:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295313#M160356</link>
      <description>&lt;P&gt;Could you link to previous question or post more details surrounding xml source code to dashboard regarding the drilldown panel? My guess without knowing everything is that the token isn't properly set to the right value. A way to debug tokens is to add script="tokens.js" to the form node&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 00:13:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295313#M160356</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-07-05T00:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295314#M160357</link>
      <description>&lt;P&gt;Cmerriman - the search is thus: index=InnerIndexHere sourcetype=InnerSourcetypeHere "ip.of.offending.addr"  | stats count BY ICID | table ICID | format&lt;/P&gt;

&lt;P&gt;This returns a subsearch of the results found in the ICID field.  I would like to the results to be capable of drilldown by clicking the contents of the cell to display the results of each ICID number (ie; was there DNS info for the IP, was it blacklisted, did it create a mid, did it close).&lt;/P&gt;

&lt;P&gt;Here is the source:&lt;/P&gt;

&lt;P&gt;true&lt;BR /&gt;
        false&lt;BR /&gt;
        none&lt;BR /&gt;
        full&lt;BR /&gt;
        1&lt;BR /&gt;
        5&lt;BR /&gt;
        full&lt;BR /&gt;
        all&lt;BR /&gt;
        1&lt;BR /&gt;
        list&lt;BR /&gt;
        cell&lt;BR /&gt;
        10&amp;lt;/option&lt;/P&gt;

&lt;P&gt;and the link to the previous question:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/552608/how-can-i-take-the-results-from-a-search-and-gener.html"&gt;https://answers.splunk.com/answers/552608/how-can-i-take-the-results-from-a-search-and-gener.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks for taking a timeout to assist on a Holiday!&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 00:26:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295314#M160357</guid>
      <dc:creator>doogan12</dc:creator>
      <dc:date>2017-07-05T00:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295315#M160358</link>
      <description>&lt;P&gt;Hmmmm - that source code didn't post correctly&lt;/P&gt;

&lt;P&gt;true&lt;BR /&gt;
        false&lt;BR /&gt;
        none&lt;BR /&gt;
        full&lt;BR /&gt;
        1&lt;BR /&gt;
        5&lt;BR /&gt;
        full&lt;BR /&gt;
        all&lt;BR /&gt;
        1&lt;BR /&gt;
        list&lt;BR /&gt;
        cell&lt;BR /&gt;
        10&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 00:28:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295315#M160358</guid>
      <dc:creator>doogan12</dc:creator>
      <dc:date>2017-07-05T00:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295316#M160359</link>
      <description>&lt;P&gt;The code falls under the option name= and are as follows - wrap, rowNumbers, dataOverlayMode, list.drolldown,list.wrap, maxLines, raw.drilldown, table.drilldown, table.wrap, type, drilldown, and count with the answer to those options listed above.&lt;/P&gt;

&lt;P&gt;TY&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 00:31:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295316#M160359</guid>
      <dc:creator>doogan12</dc:creator>
      <dc:date>2017-07-05T00:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295317#M160360</link>
      <description>&lt;P&gt;To drilldown to another search, instead of more or less opening the current search, you need to use the drilldown node. &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/Viz/ContextualDrilldown"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.2/Viz/ContextualDrilldown&lt;/A&gt;&lt;BR /&gt;
You'll need to add something like this:&lt;BR /&gt;
  &lt;CODE&gt;&lt;BR /&gt;
    &amp;lt;set token="new"&amp;gt;$click.value$&amp;lt;/set&amp;gt;&lt;BR /&gt;
    &amp;lt;/drilldown&amp;gt;&lt;/CODE&gt;&lt;BR /&gt;
And then you need to create another panel with you new search with the new token in it to use as a filter. You can add &lt;CODE&gt;depends="$new$"&lt;/CODE&gt; into the panel node to hide the panel until the token is set, if desired. &lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 00:45:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295317#M160360</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-07-05T00:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295318#M160361</link>
      <description>&lt;P&gt;Not sure what happened, but when I clicked the value returned from the original search, a new panel popped up with unexpected data in it. When I clicked the magnifying glass to 'open in search' and see what the search looked like, the search string only had the word'NULL' in it and was looking for all occurrences of NULL in the past four hours. Any thoughts on what may have occurred with the new query? &lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 21:41:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295318#M160361</guid>
      <dc:creator>doogan12</dc:creator>
      <dc:date>2017-07-05T21:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295319#M160362</link>
      <description>&lt;P&gt;Can you provide a sample of the xml so I can see where you placed the drilldown node and how you used the token in the new panel? &lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 21:51:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295319#M160362</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-07-05T21:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295320#M160363</link>
      <description>&lt;P&gt;Sure, I hope it translates properly&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  &amp;lt;title&amp;gt;ICID&amp;lt;/title&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;title&amp;gt;ICID&amp;lt;/title&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=primary sourcetype=email_server "$ip$" | stats count BY icid | table icid | format&amp;lt;/query&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;drilldown&amp;gt;
      &amp;lt;set token="show_panel"&amp;gt;true&amp;lt;/set&amp;gt;
      &amp;lt;set token="retrieve"&amp;gt;$click.value$&amp;lt;/set&amp;gt;
    &amp;lt;/drilldown&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="list.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
    &amp;lt;option name="list.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
    &amp;lt;option name="maxLines"&amp;gt;5&amp;lt;/option&amp;gt;
    &amp;lt;option name="raw.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
    &amp;lt;option name="table.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
    &amp;lt;option name="table.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
    &amp;lt;option name="type"&amp;gt;list&amp;lt;/option&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
    &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
  &amp;lt;/table&amp;gt;
&amp;lt;/panel&amp;gt;
&amp;lt;panel depends="$retrieve$"&amp;gt;
  &amp;lt;event&amp;gt;
    &amp;lt;title&amp;gt;Result of ICID search retrieval&amp;lt;/title&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=primary sourcetype=email_server $retrieve$&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;-4h@h&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="count"&amp;gt;5&amp;lt;/option&amp;gt;
  &amp;lt;/event&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 05 Jul 2017 21:57:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295320#M160363</guid>
      <dc:creator>doogan12</dc:creator>
      <dc:date>2017-07-05T21:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295321#M160364</link>
      <description>&lt;P&gt;The table you have with the ICID is using format, which would come out with one row, one column with values similar to "ICID=x OR ICID=y...". Are you trying to select just one value of ICID? You'd need to remove the format command and create an actual table. &lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 01:06:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295321#M160364</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-07-06T01:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295322#M160365</link>
      <description>&lt;P&gt;Actually, no. I want to just click the 'OR'd results.  The format command looks like it is working the way I would need it to, especially when there are multiple ICID's from a particular event. Let's say there are 10 ICID's that were found with the initial search.  Having them strung together with an OR should show the search thus: icid=123456 OR icid=234567 OR icid-345678, etc. If I go to an actual table, I'd only be able to click one at a time, and if there are 100's or thousands of icid's...you get the picture.&lt;/P&gt;

&lt;P&gt;But what I have in that query with the token $retrieve$ is returning a search with the word NULL in it.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 01:21:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295322#M160365</guid>
      <dc:creator>doogan12</dc:creator>
      <dc:date>2017-07-06T01:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295323#M160366</link>
      <description>&lt;P&gt;do you really need to have this icid=123456 OR icid=134567... in a table a clicking it or can you just show the table that would have these search results in it?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &amp;lt;panel&amp;gt;
   &amp;lt;event&amp;gt;
     &amp;lt;title&amp;gt;Result of ICID search retrieval&amp;lt;/title&amp;gt;
     &amp;lt;search&amp;gt;
       &amp;lt;query&amp;gt;index=primary sourcetype=email_server [search index=primary sourcetype=email_server "$ip$" | stats count BY icid | table icid | format] &amp;lt;/query&amp;gt;
       &amp;lt;earliest&amp;gt;-4h@h&amp;lt;/earliest&amp;gt;
       &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
     &amp;lt;/search&amp;gt;
     &amp;lt;option name="count"&amp;gt;5&amp;lt;/option&amp;gt;
   &amp;lt;/event&amp;gt;
 &amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 06 Jul 2017 11:41:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295323#M160366</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-07-06T11:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295324#M160367</link>
      <description>&lt;P&gt;If they were just laid out neatly in a table, would they be interactive or would they return a NULL?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 15:03:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295324#M160367</guid>
      <dc:creator>doogan12</dc:creator>
      <dc:date>2017-07-06T15:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295325#M160368</link>
      <description>&lt;P&gt;i figured it out. change &lt;STRONG&gt;$click.value$&lt;/STRONG&gt; to &lt;STRONG&gt;$click.value2$&lt;/STRONG&gt; when you're setting the retrieve token. that should fix the problem. &lt;BR /&gt;
here are event token definitions:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.0/Viz/EventHandlerReference#Drilldown_event_tokens"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.0/Viz/EventHandlerReference#Drilldown_event_tokens&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 15:11:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295325#M160368</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-07-06T15:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295326#M160369</link>
      <description>&lt;P&gt;Sounds great! I'll give that a try. Thank you, cmerriman!&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 15:52:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295326#M160369</guid>
      <dc:creator>doogan12</dc:creator>
      <dc:date>2017-07-06T15:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295327#M160370</link>
      <description>&lt;P&gt;Yes, it is working like I envisioned it would. Thanks for your advice.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2017 21:21:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295327#M160370</guid>
      <dc:creator>doogan12</dc:creator>
      <dc:date>2017-07-09T21:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: Drilldown on results of a subsearch not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295328#M160371</link>
      <description>&lt;P&gt;@doogan12, I did not see this until just now because you need prefix ids with the &lt;CODE&gt;@&lt;/CODE&gt; character (as in &lt;CODE&gt;@woodcock&lt;/CODE&gt;).  This will notify the user directly (like the notification that you should have just gotten).&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 02:22:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Drilldown-on-results-of-a-subsearch-not-working/m-p/295328#M160371</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-12-10T02:22:59Z</dc:date>
    </item>
  </channel>
</rss>

