Dashboards & Visualizations

Specify drill down search

paddy3883
Path Finder

I'm relatively new to Splunk and am creating a new view to display the average timings of certain events over the past 5 mins. I've created a macro search to carry out the search which takes two parameters (transaction name and duration to search), so in my first panel this is EVENT_*_LOGIN and -5m. The view currently displays a simple table of results per distinct event name.

What I would like to do is when a user clicks on a particular row it will drill down to timeline view of all events for that transaction over the past 4 hours. Is there a way to specify the information a click or drill down displays?

Apologies if this vague, please message me if more info. needed.

Tags (1)
0 Karma
1 Solution

paddy3883
Path Finder

I found the way to do this within the Advanced XML documentation

View solution in original post

0 Karma

paddy3883
Path Finder

I found the way to do this within the Advanced XML documentation

0 Karma

paddy3883
Path Finder

Hi yes I think it is, I asked the query during my initial learnings of Splunk. http://docs.splunk.com/Documentation/Splunk/latest/Viz/Dynamicdrilldownindashboardsandforms might prove useful

0 Karma

smolcj
Builder

is it possible to do it in simple xml?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...