Splunk Dev

Drilldown for Row not using the field in search if the value for the field is null

psmp
Explorer

I have a Dashboard which returns a table. the Drilldown is selected as Row for this table.

There are 2 rows with DisplayVersion as 2.8.110 and NULL.

When I click on the row with the DisplayVersion as 2.8.11.0, it opens a new window with base query that includes "search "DisplayVersion='2.8.11.0' " and return 223 rows.

But When I click the row with DisplayVersion as NULL, it opens a new window with only the base query and still returns 223 rows.

Ideally it should open the base query + "Search DisplayVersion = "" " and just display one row.

But it is not happening so. Can someone please clarify why?

Image attached for your reference.

alt text

Tags (1)
0 Karma

niketn
Legend

@psmp what is the <drilldown> code that you currently have?
Also would it be possible for you to add one sample data each for version null and version not null?

Which is the query that works fine identifying 1 null version event?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...