Dashboards & Visualizations

Base search to use in a new window as a drilldown dashboard

Explorer

Hello All,

Is there a way to put a base search in the first dashboard which drilldowns to a new dashboard where it uses the base search from the first dashboard.

0 Karma

SplunkTrust
SplunkTrust

@Nadhiya123, how many base searches are being passed from one dashboard to another? What may vary in your base searches. Can you give examples of base search from first dashboard?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

Explorer

@niketnilay

There is one search which i use to display a map in my first dashboard.

it drilldowns to the new next dashboard based on the lat/lon,

base search in 1st map dashbaord:
......
.......| stats max("count(xx)") as sessions, max(upperBound) as X, max(lowerBound) as Y by NPANXX,LAT,LNG
| geostats max(sessions) as sessions, max(X) as X, max(Y) as Y latfield=LAT longfield=LNG outputlatfield=LAT outputlongfield=LNG globallimit=0 | eval HighNoOfCalls = if(sessions > $HIGH$,sessions,0)
| eval Medium
NoOfCalls = if((sessions > $Medium$ AND sessions < $HIGH$ ),sessions,0) | eval NormalNoOf_Calls = if(sessions <= $Medium$,sessions,0)
| fields - sessions, X, Y

drilldown search 1:
.........
......| stats max("count(xx)") as sessions, max(upperBound) as X, max(lowerBound) as Y by NPANXX,LAT,LNG | eval HighNoOfCalls = if(sessions > $HIGH$,sessions,0)
| eval Medium
NoOfCalls = if((sessions > $Medium$ AND sessions < $HIGH$ ),sessions,0) | eval NormalNoOfCalls = if(sessions <=$Medium$,sessions,0) | fields - sessions, X, Y| where LAT>=$lattitude1$ AND LAT<$lattitude2$ AND LNG>=$longitude1$ AND LNG<$longitude2$|table NPANXX,HighNoOfCalls,MediumNoOfCalls,NormalNoOfCalls|where (HighNoOfCalls=$High$ AND MediumNoOfCalls=$Med$ AND NormalNoOfCalls=$Normal$) |head 1|eval HighNoOfCalls=$High$|eval MediumNoOfCalls=$Med$|eval NormalNoOfCalls=$Normal$|table NPANXX,HighNoOfCalls,MediumNoOfCalls,NormalNoOf_Calls

drilldownsearch 2:

| eventstats max("count(xx)") as sessions, max(upperBound) as X, max(lowerBound) as Y by NPANXX,LAT,LNG | eval HighNoOfCalls = if(sessions >$HIGH$,sessions,0)
| eval Medium
NoOfCalls = if((sessions > $Medium$ AND sessions < $HIGH$ ),sessions,0) | eval NormalNoOfCalls = if(sessions <=$Medium$,sessions,0) | fields - sessions, X, Y| where LAT>=$lattitude1$ AND LAT<$lattitude2$ AND LNG>=$longitude1$ AND LNG<$longitude2$
|table _time,....|where (High
NoOfCalls=$High$ AND MediumNoOfCalls=$Med$ AND NormalNoOfCalls=$Normal$) OR (MediumNoOfCalls=$Med$ AND NormalNoOfCalls=$Normal$)|sort - _time|eval m=max($High$,$Med$,$Normal$) | streamstats c | where c<=m|table ....
Trying to work on the performance issue.

Thanks

0 Karma

Legend

Hi Nadhiya123,
you can pass as token a search from the first dashboard to the second but only if it's not so long because there are limits to url lenght.
Anyway do you want to pass a fixed search or a different one depending by the click on the first dashboard panel?
Maybe you could create secondary dashboard search passing as token only parameters.

Bye.
Giuseppe

0 Karma