Dashboards & Visualizations

Specify drill down search

paddy3883
Path Finder

I'm relatively new to Splunk and am creating a new view to display the average timings of certain events over the past 5 mins. I've created a macro search to carry out the search which takes two parameters (transaction name and duration to search), so in my first panel this is EVENT_*_LOGIN and -5m. The view currently displays a simple table of results per distinct event name.

What I would like to do is when a user clicks on a particular row it will drill down to timeline view of all events for that transaction over the past 4 hours. Is there a way to specify the information a click or drill down displays?

Apologies if this vague, please message me if more info. needed.

Tags (1)
0 Karma
1 Solution

paddy3883
Path Finder

I found the way to do this within the Advanced XML documentation

View solution in original post

0 Karma

paddy3883
Path Finder

I found the way to do this within the Advanced XML documentation

0 Karma

paddy3883
Path Finder

Hi yes I think it is, I asked the query during my initial learnings of Splunk. http://docs.splunk.com/Documentation/Splunk/latest/Viz/Dynamicdrilldownindashboardsandforms might prove useful

0 Karma

smolcj
Builder

is it possible to do it in simple xml?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...