Dashboards & Visualizations

Drill Down on Stacked Bar chart

cjbanas
New Member

The chart shows number of incidents by vendor during a time period. I would like to be able to drill down on each bar for specific information about that vendor. I have 41 vendors that I monitor which may or may not show up in the chart depending on their performance for that time period. It seems as though the standard drill down function will take you to one location (i.e. search, report, chart, etc.) Is it possible to design it for drill down to each vendor listed via xml coding? I'm guessing(hopefully wrong!) that if it can be done I would need to have reports done for incidents (or the other 19KPIs) for each vendor (800 reports?) alt text

Tags (1)
0 Karma

elliotproebstel
Champion

You can use tokens to pass the value of the vendor field, for example, into the location for the drilldown. So let's say you want a click on a particular bar to take you to a search for all instances of that vendor's name in index=_internal (a strange example, but one that will at least run anywhere). Then your drilldown code would look like this:

<drilldown> 
  <link target="_blank">search?q=index=internal $click.value$</link>
</drilldown>

Here's some good documentation about using tokens in dashboards:
http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Viz/tokens

And this guide provides an overview for using tokens to make drilldowns dynamic:
http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Viz/DrilldownIntro

0 Karma

helderman
Explorer

Links are broken. Please use these: tokens, DrilldownIntro

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...