Dashboards & Visualizations

How to drilldown to a different dashboard and pass a token from a map panel on click of a value or name for a different region using a geostats search?

kkarthik2
Observer

How do I pass a token from map panel on click of a value or name for a different region using geostats?
I need the syntax and drilldown search using a token value.

0 Karma

dolivasoh
Contributor

There's an easy to read presentation from conf 2013 on this.

0 Karma

afarmer
Explorer

Thank you, dolivasoh.

I don't want to be rude and take over the thread, but maybe kkarthik2 can benefit from my post. I am able to get my maps to work now. My search string and drilldown for my map is:

index=myindex | iplocation src_ip | geostats globallimit=0 count by Country

    <drilldown>
      <set token="authcountry">$click.name$</set>
      <set token="form.authcountry">$click.name$</set>          
    </drilldown>

This successfully counts the countries and plots them on the map. However, when I click on any of the pies or circles, the $click.name$ value is always the top country in alphabetical order. For example, if I have 5 results for United Kingdom, 10 results for Italy, 2 results for Australia, and 3 results for China, when I click ANY pie or circle, the $click.name$ value will be Australia. It seems something behind the scene is sorting the countries alphabetically and choosing the top result. Do you know a way to solve this? Thanks!

0 Karma

Flynt
Splunk Employee
Splunk Employee

afarmer -I don't believe specific segments of pie can be called out for a drilldown. See this answer here if you don't mind getting all the labels and values for a pie.

http://answers.splunk.com/answers/228142/how-can-i-pass-a-token-from-a-map-panel-on-click-a.html#ans...

0 Karma

afarmer
Explorer

I would also like to know the answer.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...