Hi @Splunk_noobie, in the last drilldown, try this: <link target="_blank">https://splunk-web.com/en-US/app/publicSharing/Dashboard_second?form.instance=$instance$&form.orgId=$organizationId$&form.requestId=$row.requestId$</link> Anyway, the problem is surely in the value of the field: one time you used "form.requestId=$reqtok$" and one time you used "form.requestId=$row.requestId$". In addition I don't like to use "form.token_name", I prefer to use only "token_name". Ciao. Giuseppe
... View more