Dashboards & Visualizations

Drilldown Chart

wyang6
Path Finder

I would like to drilldown on a cell of a chart in the dashboard and use that value to re-search and display in a different panel? How should I go about doing that? Thank you.

Tags (1)
0 Karma
1 Solution

sideview
SplunkTrust
SplunkTrust

Check out the "UI Examples for 4.1" app on Splunkbase. It has numerous example views in both the simplified and advanced XML format.

Underneath 'Advanced XML', and then underneath 'Drilldown Examples' you'll see several examples of the config you're describing. It generally goes by the name "inline drilldown" or "paned viewer" configuration.

In brief, you can only do this configuration in the Advanced XML, and if you're already familiar with the advanced XML it amounts to just finding the relevant ViewRedirector module and replacing it with a different module or a different set of modules. But look at the examples in the downloadable app because they'll make more sense.

And if you arent familiar with the advanced XML yet, that app can walk you through it from a simple Hello World level.

View solution in original post

sideview
SplunkTrust
SplunkTrust

Check out the "UI Examples for 4.1" app on Splunkbase. It has numerous example views in both the simplified and advanced XML format.

Underneath 'Advanced XML', and then underneath 'Drilldown Examples' you'll see several examples of the config you're describing. It generally goes by the name "inline drilldown" or "paned viewer" configuration.

In brief, you can only do this configuration in the Advanced XML, and if you're already familiar with the advanced XML it amounts to just finding the relevant ViewRedirector module and replacing it with a different module or a different set of modules. But look at the examples in the downloadable app because they'll make more sense.

And if you arent familiar with the advanced XML yet, that app can walk you through it from a simple Hello World level.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...