Splunk Search

Timechart dynamic drilldown

Bhuavana
Explorer

Hi,

I have a timechart as my first dashboard to display all the exception types over the time and below query is used

index=test | exception_type=* | timechart count by exception_type

From above chart i need take the exception_type as input field when i click on the dashboard line.

Please share any sample code for the same.

Also how to retreive the selected value as input type in next dashboard[to display in text box]

0 Karma

Venkat_16
Contributor

Hi Bhuavana,

In the below code I have performed the dynamic drilldown by passing the exceptiontype as token. You just need to include the stanza ..

<chart>
 <searchString>index=test exception_type=* | timechart count by exception_type</searchString>
 <earliestTime>0</earliestTime>
 <latestTime>now</latestTime>
 .....
 <drilldown>
   <link>/app/your_app_name/your_next_dashboard?form.exceptiontype=$click.name2$</link>
 </drilldown>
</chart>
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...