Dashboards & Visualizations

Add a Drilldown in Splunk Dashboard with more than 60 indexes and 68 word problem?

Gordon1
Explorer

Hello everyone, 

How are you all doing? 

I have a dashboard ready. I'm having trouble placing the drilldowns.

The case is as follows: each index for example:  windows, linux, storage, would have to open a drilldown with the word problem. There are 68 worden problem and 60 indexes. 

 

Do you have any idea? 

Thank you very much!

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

OK so, on which chart or table do you want to add a drilldown?

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

It is not clear to me what you are trying to achieve. Please can you share what you currently have in your dashboard, some sample events (anonymised, of course), and what you expect to see when you click on your dashboard i.e. what the drilldown should do?

0 Karma

Gordon1
Explorer

Hello ITWhisperer, 

Thank you very much!

I am trying to show for example the result between: Linux and attack, Linus  and error, Linux and fail, Linux and failing, Linux and failed, Linux and fout.

Dan the same with Windows, firewall, aplication. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This looks like a spreadsheet rather than a Splunk dashboard. Please share what you already have in Splunk

0 Karma

Gordon1
Explorer

I made this spreadsheet with the reason you can understand what I mean. I have de dashboard. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Cool 😀 Please can you share what you already have?

0 Karma

Gordon1
Explorer

I go it!!!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

OK so, on which chart or table do you want to add a drilldown?

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...