Dashboards & Visualizations

Drilldown not working properly.

Hi All,

I have a panel containing the top 10 resolution profiles of our tickets and I want to have a drilldown table which when I click the value of the Resolution Profile, there will be a table below which contains the ticket details like ticket number and assignment group.

My drilldown works fine with the top 1 resolution profile, but when I select other resolution profiles, It gets some other ticket details which is not the one that I clicked in the table. Can you help me please with my query? Please see below query that I have.

<search>
          <query>.......| stats count by u_resolution_profiles</query>
 </search>

<drilldown>
    <set token="Value_tkn">$click.value$</set>
</drilldown>

<table depends="$Value_tkn$">
 <search>
          <query>.......|search $Value_tkn$| table ticket_number u_resolution_profiles assignment_group assigned_to| rename ticket_number as "Ticket Number" u_resolution_profiles as "Resolution Profile" assignment_group as "Assignment Group" assigned_to as "Assigned To"</query>

Thanks in advance,
Nicolo

0 Karma
1 Solution

SplunkTrust
SplunkTrust

try specifying field names in search
| search u_resolution_profiles="$Value_tkn$"

Also when you click on the panel open the drill down in the new search and look what is getting substituted. I am sure you will get an answer if you open the drilldown panel in search.

View solution in original post

SplunkTrust
SplunkTrust

try specifying field names in search
| search u_resolution_profiles="$Value_tkn$"

Also when you click on the panel open the drill down in the new search and look what is getting substituted. I am sure you will get an answer if you open the drilldown panel in search.

View solution in original post

Hi @mayurr98,

Have tried the changes and worked properly. Thanks a lot!
Hope you have a good day ahead.

All the best,
Nicolo

0 Karma

Legend

@NicoloPunzalan24, I have converted to Answers. Please Accept to mark this as answered. Also up vote the comment/s that helped 🙂

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

Communicator

Have a look at Define tokens for dynamic drilldown

I suggest the following changes:

<drilldown>
  <condition field="u_resolution_profiles">
    <set token="Value_tkn">$click.value2$</set>
  </condition>
</drilldown>

Also, change your other search to:

<query>....... | search u_resolution_profiles="$Value_tkn$" | .......
0 Karma

SplunkTrust
SplunkTrust

hey @NicoloPunzalan24
in your search query put

| search "$Value_tkn$"

"" in query and try again

let me know if it helps!

0 Karma

Hi @mayurr98,

I tried to add them but it still doesn't work. 😞

Thanks,
Nicolo

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!