Splunk Search

Drilldown query doesn't start automatically

papipaco
Engager

I'm fairly new at this, but I have done a LOT of Googling before asking here... 😉 I have a dashboard that has single-value visualizations on it. When I click on any of them, it drills down to a form with panels that contain more information (I pass values from the first dashboard to the form). The problem is that nothing starts automatically on the "detail" form. The weird part is that if I click the "Edit" button, then click "Source" and finally "Cancel," the query (and a lookup) perform as desired. Has anyone seen this? I do have autoRun="true" and submitButton="false" on the form. Thanks for any help!

Tags (1)
0 Karma
1 Solution

papipaco
Engager

And of course I find an answer after I posted...

The issue was apparently related to setting tokens in the Init section of the form. I found another answer on here that suggested setting tokens in a dummy search, and that worked like a champ. Here's the reference to that question and answer: https://answers.splunk.com/answers/449235/is-there-a-different-way-to-set-a-token-in-a-form.html

View solution in original post

0 Karma

papipaco
Engager

And of course I find an answer after I posted...

The issue was apparently related to setting tokens in the Init section of the form. I found another answer on here that suggested setting tokens in a dummy search, and that worked like a champ. Here's the reference to that question and answer: https://answers.splunk.com/answers/449235/is-there-a-different-way-to-set-a-token-in-a-form.html

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...