Dashboards & Visualizations

Splunk table: fill with previously fetched data

pshrm
New Member

I've a dashboard where one can fill the input values and hit the submit button. I execute a query and show the results in a table.
if someone clicks on a row (drilldown set on row) it opens another dashboard and show the additional information for clicked row.
Here in second dashboard, I had to execute the search query again (with tokens received from first dashboard).
Since I have all the fields from first dashboard (some fields are hidden) and I could pass them to another dashboard via setting the tokens.
Now, how can I use values of passed tokens in table of second dashboard so could avoid running the search query again.
I tried to use html table but with styling and all, i think it's an overkill for such a simple task.

Any help would be appreciated.

0 Karma

ktugwell_splunk
Splunk Employee
Splunk Employee

Hey pshrm,

If you pass the sid to the new dashboard, you can use loadjob command to retrieve the search results.

loadjob

You can access the sid by setting $job.sid$ to a token in your initial search.

          <done>
            <set token="token name">$job.sid$</set>
          </done>

Have a play with it and I hope it helps

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...