Splunk Search

getting rows from a table in a panel into another panel

lostcauz3
Path Finder

how to include specific rows from a table in a panel into another panel in the same dashboard?

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Probably a number of ways you could do this - the way I would approach it is to have a drilldown on your first panel that adds a unique identifier from the event in the first table to a token, which you then use in the search of the second panel to just retrieve those selected events. You might also want a way to reset the token. This partly depends on your data, so you would have to decide a way forward.

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

How are you specifying which rows you want in the other panel?

0 Karma

lostcauz3
Path Finder

i want to be able to choose the specific rows from the result of the table and add those in the other table

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Probably a number of ways you could do this - the way I would approach it is to have a drilldown on your first panel that adds a unique identifier from the event in the first table to a token, which you then use in the search of the second panel to just retrieve those selected events. You might also want a way to reset the token. This partly depends on your data, so you would have to decide a way forward.

0 Karma

lostcauz3
Path Finder

Thanks for your help, it was almost the exact solution i was looking for, had to slog a bit for getting it right.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...