I coded this drill down from my panel:
| eval base = "www.google.com"
| eval full = "http://www.google.com"
| eval word = "google"</query>
I want the drill down to go to the full URL that's in $row.full$. However, Splunk seems to assume this is a relative path. If I use
It works as expected. The field I want to use as a target URL has the full path in it. So I'd rather just use $row.full$ as the target.
Is there a way to tell splunk it's a full URL?
@memarshall63 try with Token Filter |n which means no filter on existing token.
View solution in original post
Nice. Thanks very much.