Dashboards & Visualizations

How to drilldown to a different dashboard and pass a token from a map panel on click of a value or name for a different region using a geostats search?

kkarthik2
Observer

How do I pass a token from map panel on click of a value or name for a different region using geostats?
I need the syntax and drilldown search using a token value.

0 Karma

dolivasoh
Contributor

There's an easy to read presentation from conf 2013 on this.

0 Karma

afarmer
Explorer

Thank you, dolivasoh.

I don't want to be rude and take over the thread, but maybe kkarthik2 can benefit from my post. I am able to get my maps to work now. My search string and drilldown for my map is:

index=myindex | iplocation src_ip | geostats globallimit=0 count by Country

    <drilldown>
      <set token="authcountry">$click.name$</set>
      <set token="form.authcountry">$click.name$</set>          
    </drilldown>

This successfully counts the countries and plots them on the map. However, when I click on any of the pies or circles, the $click.name$ value is always the top country in alphabetical order. For example, if I have 5 results for United Kingdom, 10 results for Italy, 2 results for Australia, and 3 results for China, when I click ANY pie or circle, the $click.name$ value will be Australia. It seems something behind the scene is sorting the countries alphabetically and choosing the top result. Do you know a way to solve this? Thanks!

0 Karma

Flynt
Splunk Employee
Splunk Employee

afarmer -I don't believe specific segments of pie can be called out for a drilldown. See this answer here if you don't mind getting all the labels and values for a pie.

http://answers.splunk.com/answers/228142/how-can-i-pass-a-token-from-a-map-panel-on-click-a.html#ans...

0 Karma

afarmer
Explorer

I would also like to know the answer.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...