Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do you use a custom field as a token for a drilldown?

$
0
0
I have a dashboard that contains a line chart. The query for this is something like: search ....... | rex field=_raw " (ERROR|E|SEVERE) (?[a-zA-Z0-9\. \-]*)[:\. ]" | timechart count by method limit=10 usenull=f useother=f The custom field is "method". I would like a drill-down configured so that when the user clicks on either the data point on the chart or the label name, it will take the method value and add it to the query of the "Search" dashboard. So something as simple as: search $method$ I have tried using $method$ but it literally adds "$method$" to the query. The reason I don't want to use "Auto" feature of the drilldown is that I don't want all the search arguments from the original query added to the drilldown (it's rather long and complicated). I just want the drilldown to have a simple query.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>