<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294133#M88817</link>
    <description>&lt;P&gt;Yes it does in a line underneath the Threat table. How can I pass it to the target form?&lt;/P&gt;</description>
    <pubDate>Wed, 14 Feb 2018 16:45:45 GMT</pubDate>
    <dc:creator>AbelCruz</dc:creator>
    <dc:date>2018-02-14T16:45:45Z</dc:date>
    <item>
      <title>Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294122#M88806</link>
      <description>&lt;P&gt;Good morning&lt;/P&gt;

&lt;P&gt;I am trying to drilldown from a table into another table based on the click value.&lt;BR /&gt;
The new form does open but the value is not carried over from the previous table&lt;/P&gt;

&lt;P&gt;"&lt;BR /&gt;
  McAfee&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;title&amp;gt;Host Threat correlation&amp;lt;/title&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;sourcetype=McAfee_Virus_Threat_xml | rename "EPOEvents_TargetHostName" AS "Host Name" | dedup EPOEvents_ThreatName | rename "EPOEvents_ThreatName" AS "Threat Name" | rename "EPOEvents.ThreatType" AS "Threat Type" | rename "EPO_Events_ThreatHandled" AS "Action Taken" | replace "true" with "Contained" in "Action Taken" | table  "Threat Name" "Threat Type" "Action Taken" | sort by - "Threat Type"&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;true&amp;lt;/option&amp;gt;
    &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
    &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
    &amp;lt;drilldown&amp;gt;
      &amp;lt;link&amp;gt;
          /app/search/mcafee_test?
           search sourcetype=McAfee_Virus_Threat_xml EPOEvents_ThreatName=$click_value$ | stats count by EPOEvents_TargetHostName
        &amp;lt;/link&amp;gt;
    &amp;lt;/drilldown&amp;gt;
  &amp;lt;/table&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;"&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 14:09:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294122#M88806</guid>
      <dc:creator>AbelCruz</dc:creator>
      <dc:date>2018-02-14T14:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294123#M88807</link>
      <description>&lt;P&gt;Hi @AbelCruz,&lt;BR /&gt;
you need to use &lt;CODE&gt;$click.value$&lt;/CODE&gt; instead of &lt;CODE&gt;$click_value$&lt;/CODE&gt; &lt;BR /&gt;
so try this:-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
   &amp;lt;table&amp;gt;
     &amp;lt;title&amp;gt;Host Threat correlation&amp;lt;/title&amp;gt;
     &amp;lt;search&amp;gt;
       &amp;lt;query&amp;gt;sourcetype=McAfee_Virus_Threat_xml | rename "EPOEvents_TargetHostName" AS "Host Name" | dedup EPOEvents_ThreatName | rename "EPOEvents_ThreatName" AS "Threat Name" | rename "EPOEvents.ThreatType" AS "Threat Type" | rename "EPO_Events_ThreatHandled" AS "Action Taken" | replace "true" with "Contained" in "Action Taken" | table  "Threat Name" "Threat Type" "Action Taken" | sort by - "Threat Type"&amp;lt;/query&amp;gt;
       &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
       &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
     &amp;lt;/search&amp;gt;
     &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
     &amp;lt;option name="rowNumbers"&amp;gt;true&amp;lt;/option&amp;gt;
     &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
     &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
     &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
     &amp;lt;drilldown&amp;gt;
       &amp;lt;link&amp;gt;
           /app/search/mcafee_test?
            search sourcetype=McAfee_Virus_Threat_xml EPOEvents_ThreatName=$click.value$ | stats count by EPOEvents_TargetHostName
         &amp;lt;/link&amp;gt;
     &amp;lt;/drilldown&amp;gt;
   &amp;lt;/table&amp;gt;
 &amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 14 Feb 2018 14:18:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294123#M88807</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-02-14T14:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294124#M88808</link>
      <description>&lt;P&gt;Thank you for your help.&lt;BR /&gt;
It does brings the values now but it does all of them. What I am trying to do is to click on a threat name and have Splunk to show in a new form all the affected host by that specific threat. Any suggestions ?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 14:38:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294124#M88808</guid>
      <dc:creator>AbelCruz</dc:creator>
      <dc:date>2018-02-14T14:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294125#M88809</link>
      <description>&lt;P&gt;What all values have come? also try $click.value2$ instead of $click.value$&lt;BR /&gt;
 I just tried run anywhere search and it works as expected.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
   &amp;lt;label&amp;gt;click test&amp;lt;/label&amp;gt;
   &amp;lt;row&amp;gt;
     &amp;lt;panel&amp;gt;
       &amp;lt;table&amp;gt;
         &amp;lt;title&amp;gt;search&amp;lt;/title&amp;gt;
         &amp;lt;search&amp;gt;
           &amp;lt;query&amp;gt;index=_internal | stats count by sourcetype source&amp;lt;/query&amp;gt;
           &amp;lt;earliest&amp;gt;-15m@m&amp;lt;/earliest&amp;gt;
           &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
         &amp;lt;/search&amp;gt;
         &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
         &amp;lt;option name="rowNumbers"&amp;gt;true&amp;lt;/option&amp;gt;
         &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
         &amp;lt;drilldown target="_blank"&amp;gt;
             &amp;lt;link&amp;gt;
                   &amp;lt;![CDATA[
                 /app/search/search?q=search%20index=_internal%20sourcetype=$click.value$
                  ]]&amp;gt;
               &amp;lt;/link&amp;gt;
         &amp;lt;/drilldown&amp;gt;
       &amp;lt;/table&amp;gt;
     &amp;lt;/panel&amp;gt;
   &amp;lt;/row&amp;gt;
 &amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 14 Feb 2018 15:18:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294125#M88809</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-02-14T15:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294126#M88810</link>
      <description>&lt;P&gt;$click.value$ ----&amp;gt; leftmost column value in clicked row&lt;BR /&gt;
$click.value2$ ----&amp;gt; clicked field(column) value&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 15:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294126#M88810</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-02-14T15:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294127#M88811</link>
      <description>&lt;P&gt;When I click on the threat name it shows all the hosts for all the threats not just for the specific threat that was clicked on&lt;/P&gt;

&lt;P&gt;This is what I have on the receiving form (maybe this is where the error is?&lt;/P&gt;

&lt;P&gt;McAfee test&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
  &amp;lt;chart&amp;gt;
    &amp;lt;title&amp;gt;Hosts&amp;lt;/title&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;sourcetype=McAfee_Virus_Threat_xml EPOEvents_ThreatName="*" | timechart count by EPOEvents_TargetHostName limit=0&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;1501560000&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.overflowMode"&amp;gt;ellipsisNone&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.rotation"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;collapsed&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;collapsed&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisX.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleMaximumSize"&amp;gt;50&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleMinimumSize"&amp;gt;10&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleSizeBy"&amp;gt;area&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;gaps&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.showDataLabels"&amp;gt;all&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.sliceCollapsingThreshold"&amp;gt;0.01&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.stackMode"&amp;gt;stacked&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.style"&amp;gt;shiny&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.layout.splitSeries"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.layout.splitSeries.allowIndependentYRanges"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.legend.labelStyle.overflowMode"&amp;gt;ellipsisMiddle&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.legend.placement"&amp;gt;bottom&amp;lt;/option&amp;gt;
  &amp;lt;/chart&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 14 Feb 2018 15:30:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294127#M88811</guid>
      <dc:creator>AbelCruz</dc:creator>
      <dc:date>2018-02-14T15:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294128#M88812</link>
      <description>&lt;P&gt;so are you saying &lt;CODE&gt;$click.value$&lt;/CODE&gt; becomes &lt;CODE&gt;"*"&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 16:04:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294128#M88812</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-02-14T16:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294129#M88813</link>
      <description>&lt;P&gt;Yes it does&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 16:16:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294129#M88813</guid>
      <dc:creator>AbelCruz</dc:creator>
      <dc:date>2018-02-14T16:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294130#M88814</link>
      <description>&lt;P&gt;try this for testing what value is setting in $click.value$-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;click test&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
&amp;lt;panel&amp;gt;
    &amp;lt;table&amp;gt;
      &amp;lt;title&amp;gt;Host Threat correlation&amp;lt;/title&amp;gt;
      &amp;lt;search&amp;gt;
        &amp;lt;query&amp;gt;sourcetype=McAfee_Virus_Threat_xml | rename "EPOEvents_TargetHostName" AS "Host Name" | dedup EPOEvents_ThreatName | rename "EPOEvents_ThreatName" AS "Threat Name" | rename "EPOEvents.ThreatType" AS "Threat Type" | rename "EPO_Events_ThreatHandled" AS "Action Taken" | replace "true" with "Contained" in "Action Taken" | table  "Threat Name" "Threat Type" "Action Taken" | sort by - "Threat Type"&amp;lt;/query&amp;gt;
        &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/search&amp;gt;
      &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;option name="rowNumbers"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
      &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
      &amp;lt;drilldown&amp;gt;
          &amp;lt;set token="count_field"&amp;gt;$click.value$&amp;lt;/set&amp;gt;
       &amp;lt;/drilldown&amp;gt;
    &amp;lt;/table&amp;gt;
  &amp;lt;/panel&amp;gt;
&amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;title&amp;gt;clicked value=$count_field$&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal| stats count by source&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-15m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 14 Feb 2018 16:34:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294130#M88814</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-02-14T16:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294131#M88815</link>
      <description>&lt;P&gt;It does shows the right clicked value underneath the Threat_name table&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 16:38:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294131#M88815</guid>
      <dc:creator>AbelCruz</dc:creator>
      <dc:date>2018-02-14T16:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294132#M88816</link>
      <description>&lt;P&gt;so it is showing expected value right?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 16:41:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294132#M88816</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-02-14T16:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294133#M88817</link>
      <description>&lt;P&gt;Yes it does in a line underneath the Threat table. How can I pass it to the target form?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 16:45:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294133#M88817</guid>
      <dc:creator>AbelCruz</dc:creator>
      <dc:date>2018-02-14T16:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294134#M88818</link>
      <description>&lt;P&gt;try this in drilldown; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;link&amp;gt;
            /app/search/mcafee_test?q= search sourcetype=McAfee_Virus_Threat_xml EPOEvents_ThreatName=$click.value$ | stats count by EPOEvents_TargetHostName
&amp;lt;/link&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 14 Feb 2018 16:53:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294134#M88818</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-02-14T16:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294135#M88819</link>
      <description>&lt;P&gt;This brings up a table with all the threats and hosts by time. It doesn't group the hosts by the previously selected threat name&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 17:01:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294135#M88819</guid>
      <dc:creator>AbelCruz</dc:creator>
      <dc:date>2018-02-14T17:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294136#M88820</link>
      <description>&lt;P&gt;so now &lt;CODE&gt;$click.value$&lt;/CODE&gt; is displayed as expected in new dashboard?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 17:04:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294136#M88820</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-02-14T17:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294137#M88821</link>
      <description>&lt;P&gt;This is the xml code for the destination form. Does it matter that the   EPOEvents_ThreatName is set to "*"?&lt;/P&gt;

&lt;P&gt;sourcetype=McAfee_Virus_Threat_xml EPOEvents_ThreatName="*" | timechart count by EPOEvents_TargetHostName limit=0&lt;/P&gt;

&lt;P&gt;McAfee test&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
  &amp;lt;chart&amp;gt;
    &amp;lt;title&amp;gt;Infected Host by Threat&amp;lt;/title&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;sourcetype=McAfee_Virus_Threat_xml EPOEvents_ThreatName="*" | timechart count by EPOEvents_TargetHostName limit=0&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;0&amp;lt;/earliest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.overflowMode"&amp;gt;ellipsisNone&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.rotation"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisX.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleMaximumSize"&amp;gt;50&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleMinimumSize"&amp;gt;10&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleSizeBy"&amp;gt;area&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;gaps&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.showDataLabels"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.sliceCollapsingThreshold"&amp;gt;0.01&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.stackMode"&amp;gt;default&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.style"&amp;gt;shiny&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.layout.splitSeries"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.layout.splitSeries.allowIndependentYRanges"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.legend.labelStyle.overflowMode"&amp;gt;ellipsisMiddle&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.legend.placement"&amp;gt;right&amp;lt;/option&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
  &amp;lt;/chart&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:03:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294137#M88821</guid>
      <dc:creator>AbelCruz</dc:creator>
      <dc:date>2020-09-29T18:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294138#M88822</link>
      <description>&lt;P&gt;I found a workaround for this ...but there can be better way to do this...&lt;BR /&gt;
in &lt;CODE&gt;McAfee test dashboard&lt;/CODE&gt;: here I have added hidden panel and set a token which will be used in dashboard&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel depends="$hide$"&amp;gt;&amp;lt;input type="text" token="check"&amp;gt;&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;&amp;lt;/input&amp;gt;&amp;lt;/panel&amp;gt;
&amp;lt;panel&amp;gt;
   &amp;lt;chart&amp;gt;
     &amp;lt;title&amp;gt;Infected Host by Threat&amp;lt;/title&amp;gt;
     &amp;lt;search&amp;gt;
       &amp;lt;query&amp;gt;sourcetype=McAfee_Virus_Threat_xml EPOEvents_ThreatName="$check$" | timechart count by EPOEvents_TargetHostName limit=0&amp;lt;/query&amp;gt;
       &amp;lt;earliest&amp;gt;0&amp;lt;/earliest&amp;gt;
     &amp;lt;/search&amp;gt;
     &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.overflowMode"&amp;gt;ellipsisNone&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.rotation"&amp;gt;0&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.axisX.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.axisY.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.axisY2.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.chart.bubbleMaximumSize"&amp;gt;50&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.chart.bubbleMinimumSize"&amp;gt;10&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.chart.bubbleSizeBy"&amp;gt;area&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;gaps&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.chart.showDataLabels"&amp;gt;none&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.chart.sliceCollapsingThreshold"&amp;gt;0.01&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.chart.stackMode"&amp;gt;default&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.chart.style"&amp;gt;shiny&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.layout.splitSeries"&amp;gt;0&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.layout.splitSeries.allowIndependentYRanges"&amp;gt;0&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.legend.labelStyle.overflowMode"&amp;gt;ellipsisMiddle&amp;lt;/option&amp;gt;
     &amp;lt;option name="charting.legend.placement"&amp;gt;right&amp;lt;/option&amp;gt;
     &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
     &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
     &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
     &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
   &amp;lt;/chart&amp;gt;
 &amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 14 Feb 2018 18:06:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294138#M88822</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-02-14T18:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294139#M88823</link>
      <description>&lt;P&gt;and in first dashboard add below drilldown:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &amp;lt;link&amp;gt;
             /app/search/mcafee_test?form.check=$click.value|n$
 &amp;lt;/link&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 14 Feb 2018 18:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294139#M88823</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-02-14T18:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why is drilldown from a table into another table based on the click value, does not carry the value over from the previous table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294140#M88824</link>
      <description>&lt;P&gt;Hi there&lt;BR /&gt;
Thank you for all your help&lt;BR /&gt;
Finally got it to work by using this code:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;table&amp;gt;
  &amp;lt;title&amp;gt;Detected Malware&amp;lt;/title&amp;gt;
  &amp;lt;search&amp;gt;
    &amp;lt;query&amp;gt;sourcetype=McAfee_Virus_Threat_xml EPOEvents_ThreatName="*" | rename "EPOEvents_ThreatName" AS "Threat Name" | stats count by "Threat Name"&amp;lt;/query&amp;gt;
    &amp;lt;earliest&amp;gt;-6mon&amp;lt;/earliest&amp;gt;
    &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;drilldown&amp;gt;
    &amp;lt;set token="EPOEvents_ThreatNam_tok"&amp;gt;$click.value$&amp;lt;/set&amp;gt;
  &amp;lt;/drilldown&amp;gt;
  &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
  &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
  &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
  &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
  &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
&amp;lt;/table&amp;gt;
&amp;lt;chart depends="$EPOEvents_ThreatNam_tok$"&amp;gt;
  &amp;lt;title&amp;gt;Impacted Hosts&amp;lt;/title&amp;gt;
  &amp;lt;search&amp;gt;
    &amp;lt;query&amp;gt;sourcetype=McAfee_Virus_Threat_xml EPOEvents_ThreatName="$EPOEvents_ThreatNam_tok$" | rename "EPOEvents_ThreatName" AS "Threat Name", "EPOEvents_TargetHostName" AS "Host Name" | timechart count by "Host Name" limit=0&amp;lt;/query&amp;gt;
    &amp;lt;earliest&amp;gt;-6mon&amp;lt;/earliest&amp;gt;
    &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.overflowMode"&amp;gt;ellipsisNone&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.rotation"&amp;gt;0&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.axisX.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.axisY.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.axisY2.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.chart.bubbleMaximumSize"&amp;gt;50&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.chart.bubbleMinimumSize"&amp;gt;10&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.chart.bubbleSizeBy"&amp;gt;area&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;gaps&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.chart.showDataLabels"&amp;gt;none&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.chart.sliceCollapsingThreshold"&amp;gt;0.01&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.chart.stackMode"&amp;gt;stacked&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.chart.style"&amp;gt;shiny&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.layout.splitSeries"&amp;gt;0&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.layout.splitSeries.allowIndependentYRanges"&amp;gt;0&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.legend.labelStyle.overflowMode"&amp;gt;ellipsisMiddle&amp;lt;/option&amp;gt;
  &amp;lt;option name="charting.legend.placement"&amp;gt;bottom&amp;lt;/option&amp;gt;
&amp;lt;/chart&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Again thank you for taking the time to help me out.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 19:44:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-drilldown-from-a-table-into-another-table-based-on-the/m-p/294140#M88824</guid>
      <dc:creator>AbelCruz</dc:creator>
      <dc:date>2018-02-14T19:44:38Z</dc:date>
    </item>
  </channel>
</rss>

