Hi All, I have a Dashboard and it has * | table index, URL, Volume, failure, Avg_Resp, AvgResp_Status, 90thPerc, RER, Avg_ThresholdMS, 90thPerc_ThresholdMS, Thershold_TimePeriod | sort Volume desc
I have saved this search as Dash board panel, but the URLs which are displayed on the dashboard do not have any links to "VIEW EVENT" for each URL when we click on it, can you please help how to enable this.
Thank you
Hi @rbachu1,
did you tried to enable drilldown using the URL as additional key to search?
in othe words, if you want to display all the events related to a row of a tble that have also the URL of the row, you have to put something like this:
<dashboard>
<label>Test URL</label>
<row>
<panel>
<table>
<search>
<query>
| makeresults 1 | eval URL="www.splunk.com"
| append [ | makeresults 1 | eval URL="apps.splunk.com" ]
</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
<sampleRatio>1</sampleRatio>
</search>
<option name="count">100</option>
<option name="dataOverlayMode">none</option>
<option name="drilldown">row</option>
<option name="percentagesRow">false</option>
<option name="rowNumbers">false</option>
<option name="totalsRow">false</option>
<option name="wrap">true</option>
<drilldown>
<link target="_blank">search?q=| makeresults 1 | eval URL="www.splunk.com" | append [ | makeresults 1 | eval URL="apps.splunk.com" ] | search URL=$row.URL$</link>
</drilldown>
</table>
</panel>
</row>
</dashboard>
You can find more examples about drilldown (and many other useful things) in the Splunk Dashboard Examples app ( https://splunkbase.splunk.com/app/1603/ ).
Ciao.
Giuseppe