Splunk Search

How to hide the search string from end users on drilldown of graphs/charts?

suryaavinash
Explorer

I would like to hide the SPL search query when we drill down on a chart or a graph.

I tried MACRO's and saved searches, but didn't work out. Can you please help?

It is to not expose my query to the End users.

0 Karma

somesoni2
Revered Legend

It will depending upon how you want to drilldown. For example (taking the query you gave as sample), the drilldown could be just to run another query based on col2. If that's the case, try something like this (run anywhere sample). In below example, all users would be able to see is sourcetype=ClickedValue

**All dashboard are created under "Search & Reporting" app.

Dashboard Name :thefirstdashboard

<dashboard>
  <label>thefirstdashboard</label>
  <row>
    <panel>
      <table>
        <search>
          <query>index=_internal | stats count by sourcetype</query>
          <earliest>-4h@m</earliest>
          <latest>now</latest>
        </search>
        <option name="wrap">true</option>
        <option name="rowNumbers">false</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">row</option>
        <option name="count">10</option>
        <drilldown><link>/app/search/seconddashboard?sourcetype=$row.sourcetype$</link></drilldown>
      </table>
    </panel>
  </row>
</dashboard>

Dashboard Name:seconddashboard

<dashboard>
  <label>seconddashboard</label>
  <row>
    <panel>
      <chart>
        <search>
          <query>index=_internal sourcetype=$sourcetype$| timechart count</query>
          <earliest>-4h@m</earliest>
          <latest>now</latest>
        </search>
        <option name="charting.chart">column</option>
      </chart>
    </panel>
  </row>
</dashboard>
0 Karma

somesoni2
Revered Legend

Could you explain more about your issue? Do you want to remove/hide the search string which is show in URL after drilldown? Providing your dashboard xml will help too.

0 Karma

suryaavinash
Explorer

I have created dashboards for users using splunk "dbquery" SPL command.

Ex: |dbquery "dbname" "select * from table1 where col1='xyz'" |stats count by col2

When User drills down , then i do not want him to view my query "select * from table1 where col1='xyz'".
Would like to understand how to hide the query from users view but allow him to drill down to see further results.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...