Dashboards & Visualizations

Why won't drilldown AND conditions work?

wangkevin1029
Communicator

Hi, Splunkers,

I have a condition drilldown, when I only had one condition <condition match="$t_DrillDown$ = &quot;*&quot">,  it works,   

but when I added another condition len($Gucid_token$) = 20, and click some field, which passes $Gucid_token$ as input,   my two dashboard included here are not opened, instead  a basic splunk search is opened.

 

<condition match="$t_DrillDown$ = &quot;*&quot; AND  len($Gucid_token$) = 20">
  <link target="_blank">
    <![CDATA[
      /app/optum_gvp/pivr_search?form.i_callGUID=$click.value2$&form.i_time1.earliest=$row.StartDTM_epoch$&form.i_time1.latest=$row.EndDTM_epoch$
       ]]>
   </link>
   <link target="_blank">
      <![CDATA[
        /app/optum_gvp/guciduuidsid_search_applied_rules_with_ors_log_kvp?form.Gucid_token_with2handlers=$click.value2$&form.field2.earliest=$row.StartDTM_epoch$&form.field2.latest=$row.EndDTM_epoch$
      ]]>
   </link>
</condition>

 

why added another condition  len($Gucid_token$) = 20 caused drilldown not open two dashboards , but open a basic splunk query?

 

thx.

 

Kevin

Labels (1)
0 Karma
1 Solution

wangkevin1029
Communicator

it looks I used wrong token.

 

after I changed $Gucid_token$  to  $click.value2$, it works.

 

Kevin

View solution in original post

wangkevin1029
Communicator

it looks I used wrong token.

 

after I changed $Gucid_token$  to  $click.value2$, it works.

 

Kevin

Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco &#43; Splunk! We’ve ...