Dashboards & Visualizations

Under Drilldown Custom search, eval is not working.

gpayal18
Explorer

In my drilldown editor for Pie Chart, I am using Custom search string . Inside that I'm using eval expression and saving the query.
This is the search query:
"$BuildTok1$"="" "" "$Category_token$"| convert auto("$BuildTok1$") as Actualtime |
convert auto(Requirement) as ExpectedTime | eval TestStatus=case(Actualtime==0, "NotExecuted", Actualtime <= ExpectedTime ,"Pass", Actualtime > ExpectedTime, "Fail") |sort TestStatus | table CTQID,CTQDescription, TestStatus, Requirement, Actualtime

After clicking on pie chart, it is redirecting me to blank URL.
If i use the same search query in search, it works and gives me results.

When I removed eval statement and fired query without that. pie chart click worked.
this was the query without eval:
"$BuildTok1$"="" "" "$Category_token$"| convert auto("$BuildTok1$") as Actualtime |
convert auto(Requirement) as ExpectedTime table CTQID,CTQDescription, Requirement, Actualtime

Tags (2)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@gpayal18

Have you tried with this eval in custom drilldown search?

| eval TestStatus=case(Actualtime==0, "NotExecuted", Actualtime &lt;= ExpectedTime ,"Pass", Actualtime &gt; ExpectedTime, "Fail")
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...