Dashboards & Visualizations

How can I create a dynamic drill-down without using inline searches?

KenL
Explorer

Lately I've been creating a bunch of dashboards for our vulnerability management program.  I've been creating these dashboards with dynamic drill downs.  For example, one dashboard may show user a summary view of top vulnerabilities broken down by severity and network segment, another could show historical trending of vulnerability by departments, another dashboard would compare the results from two vulnerability scans and show the differences, what's new and what's fixed.  All these dashboards allows users to drill down to view more details.  

A common theme I'm finding is that eventually the drill downs will lead the users to some elemental information such as CVE, Host, or Scan.  So in each dashboard, I would create inline searches to display these info.  For example, as users perform their drill-downs, they may arrive at a table that displays Host information, as the user click on the drill-down, a host_id token is created and passed to the inline search which uses $host_id$ as part of the query.  For each dashboard that I drill to Host Info, I would have to repeat this using inline searches with embedded $host_id$ token.  This results in many dashboards that uses basically the same search string with variable token values.

Is there a way to create a saved search that will allow tokens to be passed into the saved search, for example, host_id, starttime, endtime, so I don't have to create inline searches all over the place and if I decide the search needs to be updated, I don't have to track down every dashboard and update all inline searches?

Labels (1)
Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...