Dashboards & Visualizations

Multiple Custom Dynamic Drilldowns

mcm10285
Communicator

Is it possible to have a customized drilldown result per link? The idea is a form, which will initially result to displaying the different sourcetypes of the search, then per sourcetype result, I can drilldown to a simple table or a stats table that is created based on the sourcetype that is clicked on.

For example, the form search returned 3 sourcetypes, firewall, URL filter and AV. When I click on firewall, it will drill down to a table that shows fields related to the sourcetype (src,dst,port,etc.). Same follows for the other results when clicked on, URL filter (src,dst,URL,operation, argument,user-agent, etc.) and AV (sr,dst,signature,file,etc.)

Hope this is possible and someone can share an idea.

0 Karma

melting
Splunk Employee
Splunk Employee

Yes this is possible, there are several different techniques that can be combined:

First, custom drill down lets you specify a link to take per field/series clicked on: http://docs.splunk.com/Documentation/Splunk/6.0/Viz/Dynamicdrilldownindashboardsandforms

Second, in page drill down in Simple XML in Splunk 6.0. If you look at the Splunk 6.0 Dashboard Examples (note: requires javascript knowledge)

Lastly, use tokens to select a macro. This allows you to specify different search snippets based on user input. This is useful in either advanced xml or simple xml.

0 Karma

muellernc
Engager

I downvoted this post because link dead

0 Karma

mcm10285
Communicator

First item cannot deliver the requirement.

Second item not feasible at this time, I am at 5.0.3.

"Lastly, use tokens to select a macro. This allows you to specify different search snippets based on user input. This is useful in either advanced xml or simple xml."

--> Is this applicable to v5.0.3? Also, would you have references that you can point me to? Thanks.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...