All Apps and Add-ons

How to get field value and post it in link (Dashboard)?

sbimizry
Engager

Hi, from search ...| timechart count by status maked spikes diagram in dashboard.
Example output search:
_time 200 300 400
08/09/19 5 8 4
08/07/19 1 3 7

How to get status name (200, 300, 400) and set it in link...

<drilldown>
  <link>/apps/dashboard?form.field=$click.statusname$</link>
</drilldown>

Note:

row not worked, only all or none
$click.name$ - return field name '_time'
$click.name2$ - return field name 'count'
$click.value$ - return value field _time
$click.value$ - return value field count
0 Karma

woodcock
Esteemed Legend

You are not making sense. I used this run-anywhere search:

index=_* sourcetype=*access
|  timechart count BY status

And saved it as a dashboard panel with the Line chart visualization.
When I clicked Edit -> -> Edit drilldown and set On click to Link to search and Auto, It correctly used status=$click.name2$ as the drilldown search segment. Futhermore, if changed from Auto to Custom and used this drilldown search:

| makeresults 
| eval name="$click.name$", value="$click.value$", name2="$click.name2$", value2="$click.value2$"

I get this:

| makeresults | eval name="_time", value="1565974800.000", name2="200", value2="1014"

Which also confirms that the correct token is $click.name2$. This absolutely, positively, unquestionably IS the right answer.

0 Karma

niketn
Legend

@sbimizry try predefined drilldown token $click.name2$ as per the documentation.

https://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#Predefined_dr...

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

sbimizry
Engager

I diding it, not worked...
$click.name2$ - return field name 'count'
$click.name$ - return field name '_time'
$click.value$ - return field value '10/08/19 16:25' (one word - time)
$click.value$ - return field value count (5, 8, 4 etc)
Maybe there are other ideas?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...