Splunk Search

How to give output of first search to second search input?

frankharry
New Member

![alt text][1]I have log files with errors and warnings so my requirement is first events show only errors or warnings, if i click error messages it will show detailed summary from same log file so how to make that, I working around on this issue from past 5 to 6 days but I didn't make, any ideas?
my first search:
time|transtype|status|
6:30| harry |error |
if i click on error status it will go to events with error in this search part I need summary message from same log file.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi frankharry,

if I get you correct, you should have a look at the docs about Dynamic drill down in dashboards and forms

hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...