Splunk Search

link to search

rashid47010
Communicator

I have a coloum chart with values displaying.
I select "configure link to a search"
when I click on coloum bar it opens the results in new windows. Problem is that beside showing act=unspecified|quarantine, it get the "number/count of event"

below is my query appear in searchbar:

iindex=trend sourcetype=e** cat="*e" **act=24 | dedup fixxth | table xxcxoxt fixxaxxh act TxxrxdMxxxroxxxleSHA1

search in the drilldown editor query is below:

iindex=trend sourcetype=*e act=$click.value2$ | dedup fixxth | table xxcxoxt fixxaxxh act TxxrxdMxxxroxxxleSHA1

Please help to fix this issue.

Tags (1)
0 Karma

nickhills
Ultra Champion

If I understand your question, you want a click on a row to open a search which specifies the 'act' field in the new search?

If that's correct, try this:

index=trend sourcetype=**e* act=$row.act$ | dedup fixxth | table xxcxoxt fixxaxxh act TxxrxdMxxxroxxxleSHA1
If my comment helps, please give it a thumbs up!
0 Karma

rashid47010
Communicator

I have a chart showing top 10 values.
when I click on bar it should show me the values instead of act=24.
I want to values of that fields beside the count.

act=block|quarantine

instead of act=24

I am using act=$click.value2$ but instead taking the values=block|quarantine, he toold value(act=24)

hope you understand my query

0 Karma

rashid47010
Communicator

Dear Nick,

I have a chart showing top 10 values.
when I click on bar it should show me the values instead of act=24.
I want to values of that fields beside the count.

act=block|quarantine

instead of act=24

I am using act=$click.value2$ but instead taking the values=block|quarantine, he toold value(act=24)

hope you understand my query

0 Karma

harishalipaka
Motivator

hi @rashid47010

u want to remove that link to search ust add in your proprties..

<option name="drilldown">none</option>
*********All the Best***********
0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...