Dashboards & Visualizations

Use the "OTHER" value for token-based search

mztopp
Explorer

I have a line graph that allows me to click on the line and it populates the Country and the date/time automatically, through the drilldown/XML code, into a new search. The issue is, I have top 10 countries and the rest get consolidated into the OTHER value. Ideally, I want the OTHER value to be able to search for all of the countries not in the top 10. Right now, it's setup that if I click OTHER, then the search would just say: Country="OTHER" (which is obviously not an actual country). Any help is greatly appreciated!

Labels (2)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...