From 8.1 + : You can now use a more intuitive and better readable Syntax like index=main mysearchterm
```This is a comment```
| stats count by host
... View more
If you are using inputcsv or inputlookup , then no, you cannot. You can however use "Add data" or oneshot to send it in as events. IMHO, any set of data that does not have a timestamp inside of it should be a lookup, NOT an event.
... View more
In case it's helpful, we have some updated drilldown topics in our 6.6.x docs. The contextual drilldown topic has some examples of triggering content changes that you might find useful:
http://docs.splunk.com/Documentation/Splunk/6.6.0/Viz/ContextualDrilldown
... View more