Dashboards & Visualizations

How to use drill down search on multiple columns values to have some check on column values?

shayan_singla
New Member

There is a table with 3 columns.
On clicking one row i want that a search should get triggered and have following kind of search:

index = "user_defined" earliest="col2_value" latest="col3_value" column = "col1_value"

Please suggest the possible solution to this problem.
Thanks.

Tags (1)
0 Karma

royimad
Builder

You can use sideview and get $click.fields.someFieldName$ $click.fields.someOtherFieldName$, etc... for all the cells in the row, and you also get $click.cell0.value$, $click.cell7.value$, in case that's ever useful... then parse those values to the search

dart
Splunk Employee
Splunk Employee

are you using a Simple XML or Advanced XML Dashboard?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...