Drilldowns

A drilldown is a navigation action on a dashboard panel. When you select a value, it opens a destination you define: another dashboard, a URL, or Discover.

The destination keeps the context of that selection. That includes the value you selected, the filters on the dashboard, and the time range.

Selecting a value can also filter the dashboard you have open, for example when you select a slice or drag a time range. Add a drilldown when you want that same selection to open another view.

You can add three types of drilldown:

  • Dashboard: Open another dashboard from a panel. For example, open a host dashboard from a summary dashboard, with a filter for the host name you selected.
  • URL: Open a website from a panel. For example, open a search page that includes the host name you selected.
  • Discover: Open Discover from a visualization panel. For example, open the documents for one slice of a pie chart.
Create drilldown flyout for a URL, with Single click selected

A drilldown uses a value from a field in the data source. You cannot filter or open a drilldown from a value created at query time, because that value has no field in the index. This includes a Lens formula, an aggregation result, and an ES|QL EVAL or STATS result.

For more information about filter pills, refer to Add pills by interacting with visualizations.