Dashboards & Visualizations

Using intentions in Static html page.

sanju005ind
Communicator

I am using StaticContentSample module to display text on a panel in a view. How do I go about making the text "clickable".For example if I click on the word DNS I should get sourcetype="DNS" in the Searchbar and If I click DHCP then should get sourcetype="DHCP". Please help this is urgent.

Tags (1)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

If you're using static content, you can't use intentions. Those are only applicable in Splunk UI XML. You could use an HTML form to construct a URL like:

flashtimeline?q=search%20sourcetype%3D"DHCP"

where flashtimeline is the name of the view you want to display in (it is relative to the current view in the current app), and the value of q is simply the URL-encoding of search sourcetype="DHCP" or whatever. If you use an HTML form with method GET and send a field with the value search sourcetype="whatever", the form submission will automatically URL encode, or you can call the javascript encode() function yourself to construct the URL, or you can simply pre-encode it in the static text.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

If you're using static content, you can't use intentions. Those are only applicable in Splunk UI XML. You could use an HTML form to construct a URL like:

flashtimeline?q=search%20sourcetype%3D"DHCP"

where flashtimeline is the name of the view you want to display in (it is relative to the current view in the current app), and the value of q is simply the URL-encoding of search sourcetype="DHCP" or whatever. If you use an HTML form with method GET and send a field with the value search sourcetype="whatever", the form submission will automatically URL encode, or you can call the javascript encode() function yourself to construct the URL, or you can simply pre-encode it in the static text.

gkanapathy
Splunk Employee
Splunk Employee

add querystring parameters for "earliest_time" and "latest_time"

0 Karma

sanju005ind
Communicator

However the time range defaults to Alltime.How can I change that.

0 Karma

sanju005ind
Communicator

Thanks Kanapathy.It works for me.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...