You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Splunk饼图钻取需求:实现点击区域关联对应搜索文本

Splunk饼图钻取关联原始搜索文本的解决方案

问题核心

当前查询通过eval生成的split字段是自定义标签(count1/count2),饼图点击返回的$click.value$仅能拿到这些标签,无法直接关联到原始搜索文本(searchText1/searchText2),可通过以下两种方案解决:

方案一:修改基础查询,绑定标签与搜索文本

调整查询逻辑,同时生成自定义标签和对应的原始搜索文本字段,让饼图钻取时能直接获取到搜索词:

index=A ("searchText1" OR "searchText2") 
| eval search_term=if(match(_raw, ".*searchText1.*"), "searchText1", "searchText2")
| eval split=if(search_term="searchText1", "count1", "count2")
| chart count by split search_term
  • 钻取设置时,使用$click.value2$获取对应的search_term值(即searchText1或searchText2),以此作为关联的搜索条件。

方案二:仪表板层面添加令牌映射

无需修改基础查询,在仪表板XML的饼图组件中添加钻取逻辑,通过条件判断将自定义标签映射为原始搜索文本:

<panel>
  <chart>
    <search>
      <query>index=A ("searchText1" OR "searchText2") 
| eval split=if(match(_raw, ".*searchText1.*"), "count1", "count2") 
| chart count by split</query>
    </search>
    <drilldown>
      <condition match="$click.value$ == &quot;count1&quot;">
        <set token="drilldown_term">searchText1</set>
      </condition>
      <condition match="$click.value$ == &quot;count2&quot;">
        <set token="drilldown_term">searchText2</set>
      </condition>
    </drilldown>
  </chart>
</panel>
  • 后续关联的面板或搜索直接使用$drilldown_term$作为搜索条件即可。

内容的提问来源于stack exchange,提问作者Pavan Kumar K

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 06:05:03