Dashboards & Visualizations

Specify drill down search

paddy3883
Path Finder

I'm relatively new to Splunk and am creating a new view to display the average timings of certain events over the past 5 mins. I've created a macro search to carry out the search which takes two parameters (transaction name and duration to search), so in my first panel this is EVENT_*_LOGIN and -5m. The view currently displays a simple table of results per distinct event name.

What I would like to do is when a user clicks on a particular row it will drill down to timeline view of all events for that transaction over the past 4 hours. Is there a way to specify the information a click or drill down displays?

Apologies if this vague, please message me if more info. needed.

Tags (1)
0 Karma
1 Solution

paddy3883
Path Finder

I found the way to do this within the Advanced XML documentation

View solution in original post

0 Karma

paddy3883
Path Finder

I found the way to do this within the Advanced XML documentation

0 Karma

paddy3883
Path Finder

Hi yes I think it is, I asked the query during my initial learnings of Splunk. http://docs.splunk.com/Documentation/Splunk/latest/Viz/Dynamicdrilldownindashboardsandforms might prove useful

0 Karma

smolcj
Builder

is it possible to do it in simple xml?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...