Splunk Search

How do you customize the drilldown of a search?

heatonra
Engager

I've got a search viewed as a table and one of the values of the table cell is a URL. I want to be able to click on that URL and have the browser take me to it. My search results show that I need to customize the drilldown, but I don't see a drilldown customization in a search. Am I missing it somewhere? Is there any way to customize the drilldown of the "details" cell such that a click will take me to the URL that is the value of that cell?

Here's my (redacted) screenshot that shows what happens when I click on it (View events, Other events, etc.):

screenshot

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @heatonra

Did the answer below solve your problem? If so, please resolve this post by approving it!
If your problem is still not solved, keep us updated so that someone else can help ya. Thanks for posting!

0 Karma

gjanders
SplunkTrust
SplunkTrust

Refer to Use drilldown for dashboard interactivity if your running an older Splunk version such as 6.5.x there are other answers on SplunkAnswers or information in the documentation about editing the simpleXML for a drilldown.

In particular Link to a URL :

<link>[target_URL]?q=$[value_from_field_A]$</link>

You should be able to use your field value as part of your URL

0 Karma

kmaron
Motivator

Customizing the drill down is done with the edit options for a panel in a dashboard. (three dots - More Actions - Edit Drilldown).

Though I believe its meant just to open a specific search/dashboard/report within Splunk. I have no idea if it's possible to load a URL. Hopefully someone else can answer that part.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...