All Apps and Add-ons

drill down for field names in map not working

rucb
New Member

I am creating a map in a dashboard, my query for the map in dashboard:
search| stats sum(session_c) as No_of_calls by CO , LAT, LON|geostats values(No_of_calls) as No_of_calls latfield=LAT longfield=LON globallimit=0 by CO
so every circle in map showing CO : No_of_calls, where CO is the field name and No_of_calls is No of calls by that CO.

I have to implement drilldown and need to pass CO fieldname in another page/form but when i click any circle or any CO, its passing one same fieldname of CO in another form/page and not passing clicked/selected fieldname of CO

my drill down code :

/app/heatmap_rx/avg_total_calls?form.CO=$click.name$&form.field1.earliest=$field1.earliest$&form.field1.latest=$field1.latest$

0 Karma

niketn
Legend

@rucb, refer to one of my older answers on limitation on Map drilldown and a work-around (may not be possible if there are multiple unknown values for CO field):

https://answers.splunk.com/answers/613088/how-to-redirect-to-two-urls-from-a-cluster-map.html

Or

https://answers.splunk.com/answers/636338/why-is-the-drilldown-not-working-my-splunk-cluster.html

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

rucb
New Member

We do have values for the Central Office for example a CLLI code and the number of calls are received on a Central office. Do you think in this case it is possible ?

0 Karma

niketn
Legend

@rucb, how many distinct values of CO? Also will all CO be present in all Pies i.e. Count=0 when CO is not present?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

rucb
New Member

the count of CO is more that 10k or 25K. Yes count will be zero when not present.

0 Karma

niketn
Legend

@rucb, sorry if you have 10K-25K values which is 0 when not present, then it would mean each data point will show 25K splits. This seems to be too high, unless I have misunderstood. A mock screenshot of what you currently have will help (mask out any sensitive information).

Also, the reason why I asked above questions was that only if it is less number of splits and all the series are always present you can use approach as mentioned in above answer. Else you would need to request for an enhancement.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...