Splunk Search

How to give output of first search to second search input?

frankharry
New Member

![alt text][1]I have log files with errors and warnings so my requirement is first events show only errors or warnings, if i click error messages it will show detailed summary from same log file so how to make that, I working around on this issue from past 5 to 6 days but I didn't make, any ideas?
my first search:
time|transtype|status|
6:30| harry |error |
if i click on error status it will go to events with error in this search part I need summary message from same log file.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi frankharry,

if I get you correct, you should have a look at the docs about Dynamic drill down in dashboards and forms

hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...