Splunk Enterprise

help on click value token

jip31
Motivator

hi

Form my first panel, when I click on a row I want to display the results of the row

Actually it opens the details for all row and not for a specific wrong

What is wrong please? 

 

 

 <row>
    <panel>
      <table>
        <title>Bureau : $Site$</title>
        <search base="sante">
          <query>| stats count as "Nombre de lenteurs" by name | rename name as Nom
| sort - "Nombre de lenteurs"</query>
        </search>
        <option name="drilldown">row</option>
        <format type="color" field="Nombre de lenteurs">
          <colorPalette type="minMidMax" maxColor="#DC4E41" minColor="#FFFFFF"></colorPalette>
          <scale type="minMidMax"></scale>
        </format>
        <drilldown>
          <set token="name">$click.value$</set>
        </drilldown>
      </table>
    </panel>
    <panel depends="$name$">
      <table>
        <title>Bureau : $Site$</title>
        <search base="sante">
          <query>| stats count(web_app_duration_avg_ms) as "Nb lenteurs Web" count(hang_process_name) as "Nb hang", count(crash_process_name) as "Nb crash" by name 
| rename name as Nom</query>
        </search>
        <option name="drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </table>
    </panel>
  </row>

 

 

 

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

The search in your panel is not using the value of the $name$ token to filter the results - you are merely using the token to determine whether to display the panel or not

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The search in your panel is not using the value of the $name$ token to filter the results - you are merely using the token to determine whether to display the panel or not

0 Karma

jip31
Motivator

oh right, thanks!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...