Dashboards & Visualizations

How can I create a dynamic drill-down without using inline searches?

KenL
Explorer

Lately I've been creating a bunch of dashboards for our vulnerability management program.  I've been creating these dashboards with dynamic drill downs.  For example, one dashboard may show user a summary view of top vulnerabilities broken down by severity and network segment, another could show historical trending of vulnerability by departments, another dashboard would compare the results from two vulnerability scans and show the differences, what's new and what's fixed.  All these dashboards allows users to drill down to view more details.  

A common theme I'm finding is that eventually the drill downs will lead the users to some elemental information such as CVE, Host, or Scan.  So in each dashboard, I would create inline searches to display these info.  For example, as users perform their drill-downs, they may arrive at a table that displays Host information, as the user click on the drill-down, a host_id token is created and passed to the inline search which uses $host_id$ as part of the query.  For each dashboard that I drill to Host Info, I would have to repeat this using inline searches with embedded $host_id$ token.  This results in many dashboards that uses basically the same search string with variable token values.

Is there a way to create a saved search that will allow tokens to be passed into the saved search, for example, host_id, starttime, endtime, so I don't have to create inline searches all over the place and if I decide the search needs to be updated, I don't have to track down every dashboard and update all inline searches?

Labels (1)
Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...