Splunk Search

How to give output of first search to second search input?

frankharry
New Member

![alt text][1]I have log files with errors and warnings so my requirement is first events show only errors or warnings, if i click error messages it will show detailed summary from same log file so how to make that, I working around on this issue from past 5 to 6 days but I didn't make, any ideas?
my first search:
time|transtype|status|
6:30| harry |error |
if i click on error status it will go to events with error in this search part I need summary message from same log file.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi frankharry,

if I get you correct, you should have a look at the docs about Dynamic drill down in dashboards and forms

hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...