I have a dashboard panel that shows the sum of outbound data where I want to click on a value and display the raw events making up that data point.
The search is:
| tstats allow_old_summaries=t sum(All_Traffic.bytes_out) AS sumSent FROM datamodel="Network_Traffic" WHERE nodename="All_Traffic",("All_Traffic.app:subcategory"="file-sharing" OR "All_Traffic.app:subcategory"="database"),(All_Traffic.action="allow" OR All_Traffic.action="alert"),(All_Traffic.dest_zone="outbound"),(dest_ip!=10.0.0.0/8 OR dest_ip!=172.16.0.0/12 OR dest_ip!=192.168.0.0/16 OR dest_ip!=169.254.0.0/16) groupby _time All_Traffic.app span=10m | eval megabytes=round(((sumSent/1024)/1024),0) | timechart span=10m values(megabytes) AS MB by All_Traffic.app
Is there anything that will convert that to a Simple XML search string?
ex. Adding
<drilldown target="_blank">
<link>
<![CDATA[
/app/SplunkEnterpriseSecuritySuite/search?q=search%20$click.value2$
]]>
</link>
</drilldown>
opens a new search, but currently only passes the average of that data point on the graph. I don't understand the syntax to convert my tstats search into XML. It seems like there should be a better way to do this.
... View more