Thanks, It work ! That's my new code : <query>
index=mysourcelog "successfully" unit IN ($units_tok$)
| stats by unit
| append [ | makeresults
| eval _raw="TOTO
TUTU
TITI"
| multikv noheader=t
| rename Column_1 as unit
| stats sum(count(linecount)) by unit
</query>
<option name ="drilldown">cell</option>
<drilldown>
<set token="units_tok">"TOTO","TITI","TUTU"</set>
</drilldown> I understand now that i need to have another approch of Splunk ... I will try to variabilize the content for multikv.
... View more