Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Can't unset drilldown token in viz

$
0
0
Hi, First time poster here been lurking for too long and I just can't seem to understand where I am going wrong here... I have created a cluster map that displays the frequency of observed comms with 'bad IPs' . I want to to run a search that will return any IPs that have communicated with the selected bad ip on click, however I'm having an issue unsetting the token for a drilldown, although I am not getting any errors in the XML. It is constantly set at the first value I ever clicked on. Can anyone see any errors related to the unset in my XML? Thanks for your help in advance. Blacklisted IPs Observed| tstats summariesonly=t count FROM datamodel=Network_Traffic.All_Traffic GROUPBY All_Traffic.src_ip | rename All_Traffic.src_ip as HostAddress | lookup bad_ip.csv HostAddress OUTPUT HostAddress as ip | search ip=* | append [| tstats summariesonly=t count FROM datamodel=Network_Traffic.All_Traffic GROUPBY All_Traffic.dest_ip | rename All_Traffic.dest_ip as HostAddress | lookup bad_ip.csv HostAddress OUTPUT HostAddress as ip | search ip=*] | iplocation ip | geostats globallimit=0 count by ip-24h@hnow1$click.name$search?q=| datamodel Network_Traffic All_Traffic search| search All_Traffic.src_ip=$ip_token|s$ OR All_Traffic.dest_ip=$ip_token|s$ | table All_Traffic.src_ip ,All_Traffic.dest_ip | rename All_Traffic.src_ip as Source, All_Traffic.dest_ip as dest_ip | stats values(dest_ip) as "Destination" by Source&earliest=-24h@h&latest=now

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>