Dashboards & Visualizations

Add a Drilldown in Splunk Dashboard with more than 60 indexes and 68 word problem?

Gordon1
Explorer

Hello everyone, 

How are you all doing? 

I have a dashboard ready. I'm having trouble placing the drilldowns.

The case is as follows: each index for example:  windows, linux, storage, would have to open a drilldown with the word problem. There are 68 worden problem and 60 indexes. 

 

Do you have any idea? 

Thank you very much!

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

OK so, on which chart or table do you want to add a drilldown?

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

It is not clear to me what you are trying to achieve. Please can you share what you currently have in your dashboard, some sample events (anonymised, of course), and what you expect to see when you click on your dashboard i.e. what the drilldown should do?

0 Karma

Gordon1
Explorer

Hello ITWhisperer, 

Thank you very much!

I am trying to show for example the result between: Linux and attack, Linus  and error, Linux and fail, Linux and failing, Linux and failed, Linux and fout.

Dan the same with Windows, firewall, aplication. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This looks like a spreadsheet rather than a Splunk dashboard. Please share what you already have in Splunk

0 Karma

Gordon1
Explorer

I made this spreadsheet with the reason you can understand what I mean. I have de dashboard. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Cool 😀 Please can you share what you already have?

0 Karma

Gordon1
Explorer

I go it!!!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

OK so, on which chart or table do you want to add a drilldown?

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...