Splunk Search

Can I exclude certain columns in a table from drilldown?

mal81394
New Member

Hello,

Basically, I just want to know if there is a way in the Splunk XML to exclude certain columns in a table from drilldown making them essentially un-clickable? While others are still clickable?

Thanks

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi mal81394,

yes, you can by adding something like this:

<drilldown>
 <condition field="foo">
 </condition>
 <condition field="bar">
 </condition>
 <condition field="baz">
  <link>
    this_dashboard?form.Appname=$click.value2$
  </link>
 </condition>
</drilldown>

This will disable drill down for cells named foo and bar, but enables drill down for a cell called baz. See the docs http://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#condition_.28f... for more details on this topic.

Hope this helps ...

cheers, MuS

View solution in original post

0 Karma

kjandhyala
Explorer
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi mal81394,

yes, you can by adding something like this:

<drilldown>
 <condition field="foo">
 </condition>
 <condition field="bar">
 </condition>
 <condition field="baz">
  <link>
    this_dashboard?form.Appname=$click.value2$
  </link>
 </condition>
</drilldown>

This will disable drill down for cells named foo and bar, but enables drill down for a cell called baz. See the docs http://docs.splunk.com/Documentation/Splunk/latest/Viz/PanelreferenceforSimplifiedXML#condition_.28f... for more details on this topic.

Hope this helps ...

cheers, MuS

0 Karma

mal81394
New Member

Thanks so much!!!

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...