Hi All,
I have the following search query as a drilldown as part of the Simple XML Dashboard.
<drilldown> <link>
/app/cms-fortiweb/flashtimeline?q=`fortiweb_attack` earliest=-30d@d latest=now | search policy="$row.Policy Violations" </link> </drilldown>
I have the same drilldown added for two panels. One panel has the visualization as Table and other other as Pie chart.
So when i click on the Table to drilldown from my Dashboard, the drill down works fine by substituting the row value.
But the same does not work when i try to drilldown from a PIE Chart.
What could be the mistake here. Please provide your thoughts on this.
If you are running Splunk 6.1+, here is a simple tool to help display the available click information available on drilldown. This test tool attempts to set any/all applicable click information as tokens, and then uses an html element to render the token values.
<form>
<label>Drilldown Tester</label>
<description/>
<fieldset submitButton="false">
<input type="time" token="field1">
<label/>
<default>
<earliestTime>-60m@m</earliestTime>
<latestTime>now</latestTime>
</default>
</input>
</fieldset>
<row>
<panel>
<chart>
<searchString>index=_internal | timechart count by sourcetype</searchString>
<earliestTime>$field1.earliest$</earliestTime>
<latestTime>$field1.latest$</latestTime>
<option name="charting.drilldown">all</option>
<drilldown>
<set token="chart1.click.name">$click.name$</set>
<set token="chart1.click.name2">$click.name2$</set>
<set token="chart1.click.value">$click.value$</set>
<set token="chart1.click.value2">$click.value2$</set>
<set token="chart1.row.sourcetype">$row.sourcetype$</set>
<set token="chart1.earliest">$earliest$</set>
<set token="chart1.latest">$latest$</set>
</drilldown>
</chart>
<html>
<ul>
<li>
<code>click.name: $chart1.click.name$</code>
</li>
<li>
<code>click.name2: $chart1.click.name2$</code>
</li>
<li>
<code>click.value: $chart1.click.value|s$</code>
</li>
<li>
<code>click.value2: $chart1.click.value2|s$</code>
</li>
<li>
<code>row.sourcetype = $chart1.row.sourcetype$</code>
</li>
<li>
<code>Timerange: $chart1.earliest$ - $chart1.latest$</code>
</li>
</ul>
</html>
</panel>
</row>
</form>
Hi,
Im making use of Splunk 5.0.4 . So i dont think that i can make use of the item which you have suggested above 😞