Dashboards & Visualizations

How to drilldown to a different dashboard and pass a token from a map panel on click of a value or name for a different region using a geostats search?

kkarthik2
New Member

How do I pass a token from map panel on click of a value or name for a different region using geostats?
I need the syntax and drilldown search using a token value.

0 Karma

dolivasoh
Contributor

There's an easy to read presentation from conf 2013 on this.

0 Karma

afarmer
Explorer

Thank you, dolivasoh.

I don't want to be rude and take over the thread, but maybe kkarthik2 can benefit from my post. I am able to get my maps to work now. My search string and drilldown for my map is:

index=myindex | iplocation src_ip | geostats globallimit=0 count by Country

    <drilldown>
      <set token="authcountry">$click.name$</set>
      <set token="form.authcountry">$click.name$</set>          
    </drilldown>

This successfully counts the countries and plots them on the map. However, when I click on any of the pies or circles, the $click.name$ value is always the top country in alphabetical order. For example, if I have 5 results for United Kingdom, 10 results for Italy, 2 results for Australia, and 3 results for China, when I click ANY pie or circle, the $click.name$ value will be Australia. It seems something behind the scene is sorting the countries alphabetically and choosing the top result. Do you know a way to solve this? Thanks!

0 Karma

Flynt
Splunk Employee
Splunk Employee

afarmer -I don't believe specific segments of pie can be called out for a drilldown. See this answer here if you don't mind getting all the labels and values for a pie.

http://answers.splunk.com/answers/228142/how-can-i-pass-a-token-from-a-map-panel-on-click-a.html#ans...

0 Karma

afarmer
Explorer

I would also like to know the answer.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...