Hi My friends;
I have the following search on dashboard for the top incident review, I need when click on specific rule_name for go to incident review page for display only this incident review which I click it?
| es_notable_events
| search urgency!=low urgency!=informational | top rule_name by urgency | fields - percent
Please I need your support in that
Regards;
Pls look at the drill-down from the 'Incident Review Audit' dashboard under 'Audit' navigation menu.
So, you can setup a token for your rule_name and pass that back using incident_review?form.source.... pls check that. basically, you need to pass the rule_name to form.source... https://docs.splunk.com/Documentation/Splunk/7.2.3/Viz/DrilldownLinkToDashboard