Knowledge Management

With token values obtained from 1st dashboard on this Splunk instance, open 2nd dashboard on another Splunk instance that displays related to the token values

sssignals
Path Finder

Hi Splunk community

Is it possible to click on a row in a table, set tokens to the clicked values on a dashboard belonging to 1st splunk instance say IP address 1.2.3.4 and enable drilldown to a custom URL to another separate Splunk instance with IP address 5.6.7.8 and display panels related to the token values?

I have searched the web and my conclusion is that it cannot be done. It can only open up a dashboard on 5.6.7.8 without customizing to the token values.

Appreciate your advice on this. Many thanks in advance.

Tags (1)
0 Karma

woodcock
Esteemed Legend

What do you mean by instance? Do you mean panel or dashboard or ... ???

0 Karma

xpac
SplunkTrust
SplunkTrust

I think he means one search head and another search head...

0 Karma

xpac
SplunkTrust
SplunkTrust

Hey, did you try this?
https://answers.splunk.com/answers/457956/how-to-drill-down-from-a-splunk-dashboard-to-an-ex.html

Also note the second answer about not encoding special characters 😉

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...