Splunk Observability Cloud

How to create custom datalink in Splunk observability cloud ?

Maheswari1812
Explorer

How to create custom datalink in Splunk observability cloud for passing filtered values from chart to identify the rootcause of the issue by navigating to APM,RUM,Synthetics page.

 

 

0 Karma
1 Solution

bishida
Splunk Employee
Splunk Employee

Please review this documentation. It will guide you to creating a global data link.
https://docs.splunk.com/observability/en/metrics-and-metadata/link-metadata-to-content.html

Couple of notes to point out:
* data links are created on metadata. Things like host name, container id, etc. 
* They appear on certain types of charts, but not all. Line charts are a good example of where to find them.
* Click on any point in time on the chart and the data table will appear. The columns that contain metadata will have "..." appear in the values of that metadata where you can click to existing data links or you can start creating a new one by clicking "configure data links"
* When creating a new data link, you'll probably want to use the option "Show on any value of <your metadata field>" so that the value you have selected in your chart filter can carry through.

 

View solution in original post

bishida
Splunk Employee
Splunk Employee

Please review this documentation. It will guide you to creating a global data link.
https://docs.splunk.com/observability/en/metrics-and-metadata/link-metadata-to-content.html

Couple of notes to point out:
* data links are created on metadata. Things like host name, container id, etc. 
* They appear on certain types of charts, but not all. Line charts are a good example of where to find them.
* Click on any point in time on the chart and the data table will appear. The columns that contain metadata will have "..." appear in the values of that metadata where you can click to existing data links or you can start creating a new one by clicking "configure data links"
* When creating a new data link, you'll probably want to use the option "Show on any value of <your metadata field>" so that the value you have selected in your chart filter can carry through.

 

Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...