Dashboards & Visualizations

sub-linking a report

aniketb
Path Finder

Hi,

I have a weekly statistic report set up in Splunk for my executive. He sees a well plotted graph. As you know, if you click on any column, it'll show you the logs of the sourcetype that column is representing.

He asked me, if I click the column it should change the graph to that particular incident/sourcetype over the past week. Just the event counts but in a graph/report format.

Is it possible to do that? Will it be like linking a sub-report to a main report?

0 Karma
1 Solution

Ayn
Legend

What you're talking about (as I interpret it) is called a drilldown. The UI examples app has a number of examples on different kinds of drilldowns, I highly recommend you download it and have a look if you haven't done it already. Also, these docs sections contain useful information on creating customized drilldowns.

http://docs.splunk.com/Documentation/Splunk/latest/Developer/TableChartDrilldown
http://docs.splunk.com/Documentation/Splunk/latest/User/UnderstandTableandChartDrilldownActions

View solution in original post

Ayn
Legend

What you're talking about (as I interpret it) is called a drilldown. The UI examples app has a number of examples on different kinds of drilldowns, I highly recommend you download it and have a look if you haven't done it already. Also, these docs sections contain useful information on creating customized drilldowns.

http://docs.splunk.com/Documentation/Splunk/latest/Developer/TableChartDrilldown
http://docs.splunk.com/Documentation/Splunk/latest/User/UnderstandTableandChartDrilldownActions

aniketb
Path Finder

Exactly! Drilldown is what I was looking for!

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...