Dashboards & Visualizations

Splunk table: fill with previously fetched data

pshrm
New Member

I've a dashboard where one can fill the input values and hit the submit button. I execute a query and show the results in a table.
if someone clicks on a row (drilldown set on row) it opens another dashboard and show the additional information for clicked row.
Here in second dashboard, I had to execute the search query again (with tokens received from first dashboard).
Since I have all the fields from first dashboard (some fields are hidden) and I could pass them to another dashboard via setting the tokens.
Now, how can I use values of passed tokens in table of second dashboard so could avoid running the search query again.
I tried to use html table but with styling and all, i think it's an overkill for such a simple task.

Any help would be appreciated.

0 Karma

ktugwell_splunk
Splunk Employee
Splunk Employee

Hey pshrm,

If you pass the sid to the new dashboard, you can use loadjob command to retrieve the search results.

loadjob

You can access the sid by setting $job.sid$ to a token in your initial search.

          <done>
            <set token="token name">$job.sid$</set>
          </done>

Have a play with it and I hope it helps

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...