Splunk Enterprise Security

drill down on dashboard?

abdullahalhabba
Explorer

Hi My friends;

I have the following search on dashboard for the top incident review, I need when click on specific rule_name for go to incident review page for display only this incident review which I click it?

| es_notable_events| search urgency!=low urgency!=informational | top rule_name by urgency | fields - percent

Please I need your support in that

Regards;

0 Karma

lakshman239
Influencer

Pls look at the drill-down from the 'Incident Review Audit' dashboard under 'Audit' navigation menu.

So, you can setup a token for your rule_name and pass that back using incident_review?form.source.... pls check that. basically, you need to pass the rule_name to form.source... https://docs.splunk.com/Documentation/Splunk/7.2.3/Viz/DrilldownLinkToDashboard

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...