Splunk Search

Drilldown from Flashchart object

Ant1D
Motivator

Hey,

I have a column flashchart on a dashboard called dash_usage.xml. When I click on a bar(e.g. called User where value="Myself") on this chart, I want to be redirected to another dashboard (called dash_user_details.xml) which automatically runs a search (different to the one for the flashchart) where the field User in this search is set to the User I clicked on the previous page (i.e. Myself) and the timepicker is set to last 24 hours by default.

How can I go about achieving this?

1 Solution

ftk
Motivator

There is a detailed section on how to do this in the Developer Manual: http://www.splunk.com/base/Documentation/latest/Developer/TableChartDrilldown#Advanced_examples

Basically you have a HiddenSearch with another FlashChart.

View solution in original post

ftk
Motivator

There is a detailed section on how to do this in the Developer Manual: http://www.splunk.com/base/Documentation/latest/Developer/TableChartDrilldown#Advanced_examples

Basically you have a HiddenSearch with another FlashChart.

Ant1D
Motivator

thanks for the info. I have opened a new question

0 Karma

HattrickNZ
Motivator

wheres the link?

0 Karma

ftk
Motivator

You should be able to do that with hidden intentions. I suggest opening a new question since this is a different topic, this will give it more exposure and you can source answers from a wider range of people 🙂

0 Karma

Ant1D
Motivator

Hey FTK, if my flashchart has a number of different coloured cells (e.g. yellow = completed, blue = not_complete) How can I drill down on each cell so that clicking on blue runs a search index=a and clicking on yellow runs a search index=z ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...