All Apps and Add-ons

How do you extract drilldown from notable event and insert as a field in a grouped notable event?

allisonwalther
Path Finder

It appears that the drilldown field of a notable event disappears when that event is grouped with other events. How could I retain that information? I would like my grouped notable event to display all of the drilldowns of the events that compose it.

Single notable event has drilldown link:
alt text

Grouped notable event does not have any information about drilldown links for individual events:
alt text

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...