Dashboards & Visualizations

Why won't drilldown AND conditions work?

wangkevin1029
Communicator

Hi, Splunkers,

I have a condition drilldown, when I only had one condition <condition match="$t_DrillDown$ = &quot;*&quot">,  it works,   

but when I added another condition len($Gucid_token$) = 20, and click some field, which passes $Gucid_token$ as input,   my two dashboard included here are not opened, instead  a basic splunk search is opened.

 

<condition match="$t_DrillDown$ = &quot;*&quot; AND  len($Gucid_token$) = 20">
  <link target="_blank">
    <![CDATA[
      /app/optum_gvp/pivr_search?form.i_callGUID=$click.value2$&form.i_time1.earliest=$row.StartDTM_epoch$&form.i_time1.latest=$row.EndDTM_epoch$
       ]]>
   </link>
   <link target="_blank">
      <![CDATA[
        /app/optum_gvp/guciduuidsid_search_applied_rules_with_ors_log_kvp?form.Gucid_token_with2handlers=$click.value2$&form.field2.earliest=$row.StartDTM_epoch$&form.field2.latest=$row.EndDTM_epoch$
      ]]>
   </link>
</condition>

 

why added another condition  len($Gucid_token$) = 20 caused drilldown not open two dashboards , but open a basic splunk query?

 

thx.

 

Kevin

Labels (1)
0 Karma
1 Solution

wangkevin1029
Communicator

it looks I used wrong token.

 

after I changed $Gucid_token$  to  $click.value2$, it works.

 

Kevin

View solution in original post

wangkevin1029
Communicator

it looks I used wrong token.

 

after I changed $Gucid_token$  to  $click.value2$, it works.

 

Kevin

Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...