All Apps and Add-ons

Do Trellis also have Drilldown capability?

sarvesh_11
Communicator

alt text
Hey Folks!,

So this is the Status Indicator Visualization of 1 of my search (trellis view).

Now as an addition, how shall i move further to configure the click on this separate indicators.
Like if i click on green, a different panel should gets open.

Likewise, i tried below thing, but didnt worked out:

      <condition match="$trellis.value$ == &quot;ABC&quot;">
        <set token="ABC">ABC</set>
        <unset token="DEF"></unset>
    </condition>

When i click on any of it, is directing me to the search query of the existing panel.

0 Karma

niketn
Legend

@sarvesh_11 Trellis Layout Supports Drilldown, however, they may not work with Custom Visualizations like Status Indicator. You would need to
Option 1) Either use Simple XML JS Extension to code your own drilldown. Refer to answer: https://answers.splunk.com/answers/471329/is-it-possible-to-drilldown-from-an-status-indicat.html
Option 2) Or request and enhancement for Status Indicator Custom Visualization built by Splunk to support Drilldown. Refer to Question: https://answers.splunk.com/answers/564864/status-indicator-visualization-with-trellis-layout.html

Option 3) On similar lines with Option 1 you can also refer to another option where drilldown has been created on html panel with Status Icon and Value: https://answers.splunk.com/answers/741114/how-to-drill-down-from-custom-result-value-1.html

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

deepashri_123
Motivator

Hey@sarvesh_11,

You can refer this answer:
https://answers.splunk.com/answers/551802/how-can-i-get-drill-down-working-for-a-trellis-cha.html

Let me know if this helps!!

sarvesh_11
Communicator

@deepashri_123
Thanks for your response.
Well i have used trellis.value only, still when i click on the panel, it is opening the search of the existing panel.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...