Dashboards & Visualizations

How to show link to dashboard when view _raw in default search?

exmuzzy
Explorer

I use default search screen to see _raw such as

2017-10-26 12:41:59,787 [20    ] 
----------------------------
requestID=Server&1509010919783-704536
messageID=Message@1509010919787-907822
actor=Agent->
ip=192.168.160.10
api=EncryptApi
method=DecryptFromUID
type=request
cardUID=7F006BE8
agent=breeze

How to decorate default search view to show "requestID=Server&1509010919783-704536" as hyperlink to dashboard
/payment?requestID=Server&1509010919783-704536
?

Tags (2)
0 Karma
1 Solution

niketn
Legend

@exmuzzy, are you looking for Creating Workflow Action in Splunk: http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/SetupaGETworkflowaction

You can use Get Workflow to open a Splunk Dashboard with query string(tokens) from _raw events using field name or event type.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

@exmuzzy, are you looking for Creating Workflow Action in Splunk: http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/SetupaGETworkflowaction

You can use Get Workflow to open a Splunk Dashboard with query string(tokens) from _raw events using field name or event type.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

exmuzzy
Explorer

It's work!

0 Karma

niketn
Legend

@exmuzzy, glad it worked, I have converted to answer please accept to mark the question as answered 🙂

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...