Reporting

How to integrate Other in my search?

azeryassine
New Member

hello, 

I have a chart in my bashboard but when i click on Other, I don't have the results.

It's possible to have the logs of the hosts when I click on other?

index=firewall AND sourcetype=cisco:ios AND host="*r01p" OR "*r01s"| chart count by host | rename count as NumberEvent

it's not possible to use the option useother=true  for chart ?

 

 

Labels (3)
0 Karma

gcusello
Legend

Hi @azeryassine,

you should configure drilldown in another dashboard and in the secondary dashboard set the condition

| eval host=if(host="Other","*",host)

 Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...

DevSecOps: Why You Should Care and How To Get Started

 WATCH NOW In this Tech Talk we will talk about what people mean by DevSecOps and deep dive into the different ...

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...