Dashboards & Visualizations

Dashboard drilldown conditions

klaudiac
Path Finder

Hi folks, 

Quick question, but I'm running out of ideas.

I have a dashboard where I compare results between US and EU, one of the filters is "side" where I differentiate between EU and US. 

When I select EU results, I'd like to be able to click on a result and it'll open up a new window with details of how that result was achieved (it's from another website)
Same scenario  for when i click on the Side=NA, it leads me to a different website.

I tried this, but as far as the EU part work, the US does not... 

 

<drilldown>
<condition match="$side$ = EU"></condition>
<condition>
<link target="_blank">/app/SplunkEnterpriseSecuritySuite/correlation_search_edit?search=$row.rule_name$</link>
</condition>

<condition match="$side$ = US"></condition>
<condition>
<link target="_blank">www.youtube.com</link>
</condition>
</drilldown>

 

Any hints or ideas? 

 

Thanks, 

Klaudia 

Labels (3)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

@klaudiac 

You condition statements don't make sense. You have 4 conditions there, two are empty, i.e. 

 

<condition match="$side$ = EU"></condition>

 

does not do anything, so all you have there is a single drilldown, which will most likely be the first one Splunk comes across, i.e. the link to the ES correlation search edit

 Try this - note the &quot; values before and after the EU/ES, as they should be quoted for string matching.

 

<drilldown>
  <condition match="$side$ = &quot;EU&quot;">
    <link target="_blank">/app/SplunkEnterpriseSecuritySuite/correlation_search_edit?search=$row.rule_name$</link>
  </condition>
  <condition match="$side$ = &quot;US&quot;">
    <link target="_blank">www.youtube.com</link>
  </condition>
</drilldown>

 

 

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

@klaudiac 

You condition statements don't make sense. You have 4 conditions there, two are empty, i.e. 

 

<condition match="$side$ = EU"></condition>

 

does not do anything, so all you have there is a single drilldown, which will most likely be the first one Splunk comes across, i.e. the link to the ES correlation search edit

 Try this - note the &quot; values before and after the EU/ES, as they should be quoted for string matching.

 

<drilldown>
  <condition match="$side$ = &quot;EU&quot;">
    <link target="_blank">/app/SplunkEnterpriseSecuritySuite/correlation_search_edit?search=$row.rule_name$</link>
  </condition>
  <condition match="$side$ = &quot;US&quot;">
    <link target="_blank">www.youtube.com</link>
  </condition>
</drilldown>

 

 

0 Karma

klaudiac
Path Finder

That worked, thanks so much! 

0 Karma

to4kawa
Ultra Champion
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...