I am trying to create a drill down dashboard. Basically I want to pass a subnet value (which is currently represented as a string) from one pane to another search pane and search on data in that query using the subnet value. I have tried several methods and none seem to work.
Ideally I thought something like the below would work in pseudo code.
Search ... |
eval subnet_value=$subnet value from first query$ |
However, I get back no results. Perhaps someone has some tips on some things I can try next as I am stuck currently.
you can't compare ipv4 with subnet (for example 10.10.10.0/24) as you mentioned in your pseudo code
instead, you get value to current search from other dashboard ( I believe your subnet value coming from dashboard would be something like 10.10.10.0/24 ). you can write this value to lookup using outputlookup command from current search. define lookup where lookup can match cidr for specified field.
and then you have to use lookup command instead of where like above.