I currently have a timechart in Splunk that shows an average for each day (span=day). I want to be able to click the timechart and drill down to a view that shows the events that were logged on that day. How do I get the token for the timespan of a single day to pass as a token into another dashboard?
hi edyke
dashboardexample6.x app will be help you .
install this app and go see his drilldown example
Check this out: http://docs.splunk.com/Documentation/Splunk/6.2.2/Viz/PanelreferenceforSimplifiedXML#chart_.28event_...
In essence, you get two tokens $earliest$
and $latest$
that contain the time range you clicked on. If you clicked on a day, it's that day. If you clicked on the legend, it's the entire timechart.
Can you post your dashboard code please?