Splunk Search

Question on base search

prettysunshinez
Explorer

Hi I have the below post process search but little confused on the base search.Kindly help.

Post process search:
Search id="base"
Query - index = |regex for field1 | regex for field2| regex for field3 | chart count over field1 by field4(already extracted one)

Now i would like to perform a cell drilldown and on clicking a value field1 i want the below 3 panels to be dispayed

Panel 2 : where field1 =$field1$ | stats count by field4
Panel 3 : where field1 =$field1$ | table _time _ raw
Panel 4 :where field1 =$field1$ | stats count by field3

How can i achieve this.
Timechart to stats
& To raw logs

Tags (1)
0 Karma

prettysunshinez
Explorer

Any help pls

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...