Splunk Enterprise

help on click value token

jip31
Motivator

hi

Form my first panel, when I click on a row I want to display the results of the row

Actually it opens the details for all row and not for a specific wrong

What is wrong please? 

 

 

 <row>
    <panel>
      <table>
        <title>Bureau : $Site$</title>
        <search base="sante">
          <query>| stats count as "Nombre de lenteurs" by name | rename name as Nom
| sort - "Nombre de lenteurs"</query>
        </search>
        <option name="drilldown">row</option>
        <format type="color" field="Nombre de lenteurs">
          <colorPalette type="minMidMax" maxColor="#DC4E41" minColor="#FFFFFF"></colorPalette>
          <scale type="minMidMax"></scale>
        </format>
        <drilldown>
          <set token="name">$click.value$</set>
        </drilldown>
      </table>
    </panel>
    <panel depends="$name$">
      <table>
        <title>Bureau : $Site$</title>
        <search base="sante">
          <query>| stats count(web_app_duration_avg_ms) as "Nb lenteurs Web" count(hang_process_name) as "Nb hang", count(crash_process_name) as "Nb crash" by name 
| rename name as Nom</query>
        </search>
        <option name="drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </table>
    </panel>
  </row>

 

 

 

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

The search in your panel is not using the value of the $name$ token to filter the results - you are merely using the token to determine whether to display the panel or not

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The search in your panel is not using the value of the $name$ token to filter the results - you are merely using the token to determine whether to display the panel or not

0 Karma

jip31
Motivator

oh right, thanks!

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...