Dashboards & Visualizations

How to show link to dashboard when view _raw in default search?

exmuzzy
Explorer

I use default search screen to see _raw such as

2017-10-26 12:41:59,787 [20    ] 
----------------------------
requestID=Server&1509010919783-704536
messageID=Message@1509010919787-907822
actor=Agent->
ip=192.168.160.10
api=EncryptApi
method=DecryptFromUID
type=request
cardUID=7F006BE8
agent=breeze

How to decorate default search view to show "requestID=Server&1509010919783-704536" as hyperlink to dashboard
/payment?requestID=Server&1509010919783-704536
?

Tags (2)
0 Karma
1 Solution

niketn
Legend

@exmuzzy, are you looking for Creating Workflow Action in Splunk: http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/SetupaGETworkflowaction

You can use Get Workflow to open a Splunk Dashboard with query string(tokens) from _raw events using field name or event type.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

@exmuzzy, are you looking for Creating Workflow Action in Splunk: http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/SetupaGETworkflowaction

You can use Get Workflow to open a Splunk Dashboard with query string(tokens) from _raw events using field name or event type.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

exmuzzy
Explorer

It's work!

0 Karma

niketn
Legend

@exmuzzy, glad it worked, I have converted to answer please accept to mark the question as answered 🙂

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...