Dashboards & Visualizations

How do you manipulate a token before passing it to a drilldown?

splunkrocks2014
Communicator

How do you manipulate a token before passing it to a drilldown?

For example, the following dashboard has a a statistic table with a field, country with value "United States of America (USA)", and I just want to pass "USA" to the drilldown. But the token ("country") is not changed to "USA" from the eval function when passed to the deep link. Any clues? Thanks.

<dashboard>
  <label>testing</label>
  <row>
    <panel>
      <table>
        <search>
          <query>| makeresults
| eval Country="United States of America (USA)"
| table Country</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
          <sampleRatio>1</sampleRatio>
        </search>
        <option name="count">100</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">row</option>
        <option name="percentagesRow">false</option>
        <option name="rowNumbers">false</option>
        <option name="totalsRow">false</option>
        <option name="wrap">true</option>
        <drilldown>
          <eval token="country">replace(replace(mvindex(split($click.value$," "),-1,-1),"\(",""),"\)","")</eval>
          <link target="_blank">
            <![CDATA[https://en.wikipedia.org/wiki/$country$]]>
          </link>
        </drilldown>
      </table>
    </panel>
  </row>
</dashboard>
0 Karma
1 Solution

renjith_nair
Legend

@splunkrocks2014 ,

It's possible to change but why don't you extract in the search itself? For e.g.

<dashboard>
  <label>testing</label>
  <row>
    <panel>
      <table>
        <search>
          <query>| makeresults
| eval Country="United States of America (USA)"
| rex field="Country" "\((?<_C>.*)\)"</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
          <sampleRatio>1</sampleRatio>
        </search>
        <option name="count">100</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">row</option>
        <option name="percentagesRow">false</option>
        <option name="rowNumbers">false</option>
        <option name="totalsRow">false</option>
        <option name="wrap">true</option>
        <drilldown>
          <link target="_blank">
            <![CDATA[https://en.wikipedia.org/wiki/$row._C$]]>
          </link>
        </drilldown>
      </table>
    </panel>
  </row>
</dashboard>
Happy Splunking!

View solution in original post

renjith_nair
Legend

@splunkrocks2014 ,

It's possible to change but why don't you extract in the search itself? For e.g.

<dashboard>
  <label>testing</label>
  <row>
    <panel>
      <table>
        <search>
          <query>| makeresults
| eval Country="United States of America (USA)"
| rex field="Country" "\((?<_C>.*)\)"</query>
          <earliest>-15m</earliest>
          <latest>now</latest>
          <sampleRatio>1</sampleRatio>
        </search>
        <option name="count">100</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">row</option>
        <option name="percentagesRow">false</option>
        <option name="rowNumbers">false</option>
        <option name="totalsRow">false</option>
        <option name="wrap">true</option>
        <drilldown>
          <link target="_blank">
            <![CDATA[https://en.wikipedia.org/wiki/$row._C$]]>
          </link>
        </drilldown>
      </table>
    </panel>
  </row>
</dashboard>
Happy Splunking!

splunkrocks2014
Communicator

Never thought about this way 🙂 ... thanks.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...