Dashboards & Visualizations

How to drill down from a table into a chart within the same dashboard

shanksholla
Explorer

Hi
I have a table in my dashboard which displays total number of hits and the average response time for each operation.

index=gwlogs service=customer | stats count(operation_name) avg(transaction_time) by operation_name

A drill down for the table is present which provides the error code along with the count for the chosen operation. This appears in a new tab.



<![CDATA[/app/search/search?q=search index=gwlogs service=customer operation_name=$click.value$ | stats count by error_code&earliest=$earliest$&latest=$latest$]]>

Is it possible to have the drilled down chart appear below the initial table itself.

Thank you!

Tags (2)
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Add a chart to the dashboard below the table, and include a $foo$ token for your value. Change your link tag within the drilldown to a set tag and set the token to $click.value$. Something like this:

...
  <drilldown>
    <set token="foo">$click.value$</set>
  </drilldown>
...
<chart>
  <searchString>index=gwlogs service=customer operation_name="$foo$" | ...</searchString
...
</chart>
...

http://docs.splunk.com/Documentation/Splunk/6.1.2/Viz/PanelreferenceforSimplifiedXML#set

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Add a chart to the dashboard below the table, and include a $foo$ token for your value. Change your link tag within the drilldown to a set tag and set the token to $click.value$. Something like this:

...
  <drilldown>
    <set token="foo">$click.value$</set>
  </drilldown>
...
<chart>
  <searchString>index=gwlogs service=customer operation_name="$foo$" | ...</searchString
...
</chart>
...

http://docs.splunk.com/Documentation/Splunk/6.1.2/Viz/PanelreferenceforSimplifiedXML#set

shanksholla
Explorer

This gave me what I wanted. Thank you!

0 Karma

nfilippi_splunk
Splunk Employee
Splunk Employee

Yes, use the depends and/or rejects attribute for your element


index=gwlogs service=customer operation_name="$foo$" | ... ...

More info here:
http://docs.splunk.com/Documentation/Splunk/6.1.2/Viz/Understandbasictableandchartdrilldownactions#C...

shanksholla
Explorer

Hi, thanks for your reply. This partially solves my problem. With this there is any empty chart before any row is clicked. Can I make the charts appear only after a row is clicked?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...