I have 2 chart (1. Top 10 Signature) (2. Source IP Address)
My query can show overall event but can't show specific event when click.
This is my query.
On chart "Top 10 Signature" host="SRV-IPS-MGMT" NOT SyslogAuditLogForwarder | stats count by ips_name | sort 10 - count On chart "Source IP Address" host="SRV-IPS-MGMT" NOT SyslogAuditLogForwarder | stats count by ips_src_ip | sort - count
I'm set token of Edit Drilldown on chart "Top 10 Signature" because i want to show only event of signature that i'm click on chart "Source IP Address" but i don't know how to use condition search.
I want use condition like
if token="do not have value" do "query1"
else do "query2"
Have you looked at https://docs.splunk.com/Documentation/Splunk/7.2.3/Viz/ContextualDrilldown?
you can go specific via drill-down search from your top panel.
In the above, as your base search is same, you can also look at base and post-process search to improve performance.