Dashboards & Visualizations

Interactive dashboard drilldown

doronca
Explorer

Hello Splunkers,

I am trying to have an interactive dashboard where one dashboard is feeding the another with data for searches.

Dashboard 1:
I set a token in one of my visualizations that redirect to the second dashboard and should pass a "tok_incident" parameter. As suggested in splunk documentation I added "form" as a prefix:

  <table depends="$showTableI$">
    <search>
      <query>| `all_alerts` | fillnull value="unknown" owner, status, status_description, impact, urgency, priority | rename tags as tactic | rename priority as severity | join job_id[search index="demisto" | spath id | spath job_id]  | rename id as "ID" | sort - _time | table alert, "ID"</query>
      <earliest>$global_time.earliest$</earliest>
      <latest>$global_time.latest$</latest>
    </search>
    <option name="count">3</option>
    <option name="dataOverlayMode">none</option>
    <option name="drilldown">cell</option>
    <option name="percentagesRow">false</option>
    <option name="refresh.display">progressbar</option>
    <option name="rowNumbers">false</option>
    <option name="totalsRow">false</option>
    <option name="wrap">true</option>
    <format type="color" field="%">
      <colorPalette type="list">[#5378AD, #98BF3B, #F0BE1B, #FF8800, #D25B3B]</colorPalette>
      <scale type="threshold">15,30,50,75,90</scale>
    </format>
    <drilldown>
      <link target="_blank">/app/app/incident_enrichment?form.tok_incident=$row.ID$</link>
    </drilldown>
  </table>

Dashboard 2:
The second dashboard includes several searches that should get in the "tok_incident" value.
Also, I set the initial value to "*" as seen below:

 <init>
    <set token="tok_incident">*</set>
  </init>

Search for example:

<panel>
  <title>Malicious Files Observed</title>
  <viz type="parallel_coordinates_app.parallel_coordinates">
    <search>
      <query>index="demisto" | spath id  | search id="$tok_incident$"| spath "RL.results{}.aliases{}" | rename "RL.results{}.aliases{}" as MaliciousFileName | stats count by MaliciousFileName</query>
      <earliest>$global_time.earliest$</earliest>
      <latest>$global_time.latest$</latest>
    </search>
    <option name="drilldown">all</option>
    <option name="refresh.display">progressbar</option>
    <option name="trellis.enabled">0</option>
  </viz>
</panel>

The problem:
Although the value passes through the URL I still get all data, as defined in <init> and not the passed value within "tok_incident" token.

any help?

Doron

Tags (2)
0 Karma
1 Solution

renjith_nair
Legend

@doronca,

When the dashboard loads, the init event get activated and set the token value. Even though we are passing the value in the URL, there is no other event which resets the token to the passed URL value.

One of the options is to use an input element instead of the init function and load it with the defaut value

For e.g

In the first dashboard, we set the form elements as usual

<dashboard>
  <row>
    <panel>
      <table>
        <search>
          <query>index=_*|stats count by sourcetype</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">cell</option>
        <drilldown>
          <link target="_blank">/app/search/dashboard2?form.sourcetype=$row.sourcetype$</link>
        </drilldown>
      </table>
    </panel>
  </row>
</dashboard>

In the second dashboard, instead of an init event, add a dummy input element (hidden) so that we can set it's token by passing value through URL

<form>
  <label>Dashboard2</label>
    <fieldset submitButton="false">
    <input type="dropdown" token="sourcetype" depends="$hiddenAlways$">
      <label>field1</label>
      <default>*</default>
      <initialValue>*</initialValue>
      <choice value="*">All</choice>
    </input>
  </fieldset>  
  <row>
    <panel>
      <chart>
        <search>
          <query>index=_internal sourcetype="$sourcetype$"|stats count by sourcetype</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="charting.chart">pie</option>
        <option name="charting.drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </chart>
    </panel>
  </row>
</form>

You could use any input type there - just set the initial value and default value to *.

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

@doronca,

When the dashboard loads, the init event get activated and set the token value. Even though we are passing the value in the URL, there is no other event which resets the token to the passed URL value.

One of the options is to use an input element instead of the init function and load it with the defaut value

For e.g

In the first dashboard, we set the form elements as usual

<dashboard>
  <row>
    <panel>
      <table>
        <search>
          <query>index=_*|stats count by sourcetype</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">cell</option>
        <drilldown>
          <link target="_blank">/app/search/dashboard2?form.sourcetype=$row.sourcetype$</link>
        </drilldown>
      </table>
    </panel>
  </row>
</dashboard>

In the second dashboard, instead of an init event, add a dummy input element (hidden) so that we can set it's token by passing value through URL

<form>
  <label>Dashboard2</label>
    <fieldset submitButton="false">
    <input type="dropdown" token="sourcetype" depends="$hiddenAlways$">
      <label>field1</label>
      <default>*</default>
      <initialValue>*</initialValue>
      <choice value="*">All</choice>
    </input>
  </fieldset>  
  <row>
    <panel>
      <chart>
        <search>
          <query>index=_internal sourcetype="$sourcetype$"|stats count by sourcetype</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
        </search>
        <option name="charting.chart">pie</option>
        <option name="charting.drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </chart>
    </panel>
  </row>
</form>

You could use any input type there - just set the initial value and default value to *.

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...