Dashboards & Visualizations

How can I create a dynamic drill-down without using inline searches?

KenL
Explorer

Lately I've been creating a bunch of dashboards for our vulnerability management program.  I've been creating these dashboards with dynamic drill downs.  For example, one dashboard may show user a summary view of top vulnerabilities broken down by severity and network segment, another could show historical trending of vulnerability by departments, another dashboard would compare the results from two vulnerability scans and show the differences, what's new and what's fixed.  All these dashboards allows users to drill down to view more details.  

A common theme I'm finding is that eventually the drill downs will lead the users to some elemental information such as CVE, Host, or Scan.  So in each dashboard, I would create inline searches to display these info.  For example, as users perform their drill-downs, they may arrive at a table that displays Host information, as the user click on the drill-down, a host_id token is created and passed to the inline search which uses $host_id$ as part of the query.  For each dashboard that I drill to Host Info, I would have to repeat this using inline searches with embedded $host_id$ token.  This results in many dashboards that uses basically the same search string with variable token values.

Is there a way to create a saved search that will allow tokens to be passed into the saved search, for example, host_id, starttime, endtime, so I don't have to create inline searches all over the place and if I decide the search needs to be updated, I don't have to track down every dashboard and update all inline searches?

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...