Hi Everyone,
I have one requirement . Below is my search query for my failed RID's
index=ABC ns=xyz app_name=abc "ARC FAILED TO UPDATE RESPONSE BACK TO SOURCE OR SF"|rex "RID:(?<RID>(\w+-){4}\w+)-(?<sourceagent>\w+-\w+)"
| eval count=1
| table RID, sourceagent, count | rename sourceagent as "Source".
I am getting like below:
RID Source count
f56bce02-750d-451c-a341-4769d7518f2c | of1-team_b | 1 |
c09b64eb-45c3-4fcb-9deb-81faa3d5c98b | of1-team_b | 1 |
I want when I click in the first row it should show the raw logs for failed RID's and that panel should be hidden It should be only show when we click on particular rows which we want to see.
Below are my raw logs for 1st failed RID:
020-10-01T09:20:57.829079909Z app_name=api environment=e3 ns=c2 pod_container=api pod_name=bhhf5 message=2020-10-01 02:20:57.826 ERROR [service,,,] 1 --- [or-http-epoll-3] c.a.b.a.c.s.impl.SFCallbackService : RID:f56bce02-750d-451c-a341-4769d7518f2c-of1-team_b-ivurtupload EL:1601: ARC FAILED TO UPDATE RESPONSE BACK TO SOURCE OR SF Reason:404 Not Found: [[ {
Can someone guide me how can I achieve that?
<set token="selected_value">$click.value2$</set>
<query>index=ABC ns=xyz app_name=abc "ARC FAILED TO UPDATE RESPONSE BACK TO SOURCE OR SF" $selected_value$
</query>
Your "hidden" panel should have a query based on a token (the RID you want to search for). The first panel then need a drilldown which sets the token with the value from the RID column for the row that is clicked. It should also set the token that the hidden panel depends on (this could possibly be the same token).
Thank you so much for suggestion.
Can you please provide me with the query if possible. It would be a great help.
I just want to display the raw data on clicking of RID's so that we get the detailed failed description.
Thanks in advance.
index=ABC ns=xyz app_name=abc "ARC FAILED TO UPDATE RESPONSE BACK TO SOURCE OR SF"|rex "RID:(?<RID>(\w+-){4}\w+)-(?<sourceagent>\w+-\w+)"
| where RID=$ridTokenSetByDrilldown$
I have tried with below code but not working where I have gone wrong.
<dashboard>
<label>jkt</label>
<fieldset submitButton="false">
<input type="time" token="field1">
<label></label>
<default>
<earliest>-7d@h</earliest>
<latest>now</latest>
</default>
</input>
</fieldset>
<row>
<panel>
<table>
<search>
<query>index=ABC ns=xyz app_name=abc"ARC FAILED TO UPDATE RESPONSE BACK TO SOURCE OR SF"| rex "RID:(?<RID>(\w+-){4}\w+)-(?<sourceagent>\w+-\w+)"
| eval count=1
| table RID, sourceagent count| rename sourceagent as "Source"</query>
<earliest>$field1.earliest$</earliest>
<latest>$field1.latest$</latest>
<sampleRatio>1</sampleRatio>
</search>
<option name="count">100</option>
<option name="dataOverlayMode">none</option>
<option name="drilldown">row</option>
<option name="percentagesRow">false</option>
<option name="rowNumbers">false</option>
<option name="totalsRow">false</option>
<option name="wrap">true</option>
<drilldown>
<set token="show_panel">true</set>
<set token="selected_value">$ridTokenSetByDrilldown$</set>
</drilldown>
</table>
</panel>
</row>
<row>
<panel depends="$show_panel$">
<table>
<title>Caller Details</title>
<search>
<query>index=ABC ns=xyz app_name=abc "ARC FAILED TO UPDATE RESPONSE BACK TO SOURCE OR SF"|rex "RID:(?<RID>(\w+-){4}\w+)-(?<sourceagent>\w+-\w+)" $selected_value$
</query>
<earliest>$field1.earliest$</earliest>
<latest>$field1.latest$</latest>
</search>
<option name="count">100</option>
</table>
</panel>
</row>
</dashboard>
<set token="selected_value">$click.value2$</set>
<query>index=ABC ns=xyz app_name=abc "ARC FAILED TO UPDATE RESPONSE BACK TO SOURCE OR SF" $selected_value$
</query>