Hi, i've been trying to fix this for the last 4 hours. I'm evaluating a value in a drilldown. The evaluated value isn't literally being passed into the link token value i've specified. Instead the token name is being passed into the link. I've looked through the docs and similar issues in this forum but nothing explains the problem i'm having. I'm on Splunk Version 6.2.5 Splunk Build 272645 Simple xml below Any help would be amazing. <drilldown target="blank">
<eval token="trunc_host">rex field=host mode=sed "s/\d+/"*"/g"|</eval>
<link>
<![CDATA[
Integration_PRA_capacity_breakdown?form.host=$trunc_host$&form.stack=$row.stack$&earliest=-h$&latest=now
]]>
</link>
</drilldown> This is the url generated https://url/app/excd/Int_PR_city_break?form.host=%24trunc_host%24&form.stack=inst&earliest=-h%24&latest=now
... View more