Splunk Search

How to give output of first search to second search input?

frankharry
New Member

![alt text][1]I have log files with errors and warnings so my requirement is first events show only errors or warnings, if i click error messages it will show detailed summary from same log file so how to make that, I working around on this issue from past 5 to 6 days but I didn't make, any ideas?
my first search:
time|transtype|status|
6:30| harry |error |
if i click on error status it will go to events with error in this search part I need summary message from same log file.

0 Karma

MuS
Legend

Hi frankharry,

if I get you correct, you should have a look at the docs about Dynamic drill down in dashboards and forms

hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...