Dashboards & Visualizations

How can I create a dynamic drill-down without using inline searches?

KenL
Explorer

Lately I've been creating a bunch of dashboards for our vulnerability management program.  I've been creating these dashboards with dynamic drill downs.  For example, one dashboard may show user a summary view of top vulnerabilities broken down by severity and network segment, another could show historical trending of vulnerability by departments, another dashboard would compare the results from two vulnerability scans and show the differences, what's new and what's fixed.  All these dashboards allows users to drill down to view more details.  

A common theme I'm finding is that eventually the drill downs will lead the users to some elemental information such as CVE, Host, or Scan.  So in each dashboard, I would create inline searches to display these info.  For example, as users perform their drill-downs, they may arrive at a table that displays Host information, as the user click on the drill-down, a host_id token is created and passed to the inline search which uses $host_id$ as part of the query.  For each dashboard that I drill to Host Info, I would have to repeat this using inline searches with embedded $host_id$ token.  This results in many dashboards that uses basically the same search string with variable token values.

Is there a way to create a saved search that will allow tokens to be passed into the saved search, for example, host_id, starttime, endtime, so I don't have to create inline searches all over the place and if I decide the search needs to be updated, I don't have to track down every dashboard and update all inline searches?

Labels (1)
Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...