I'm trying to configure drilldown functionality on a Table widget in Google SecOps Dashboards, where one of the displayed fields is an array (repeated field). I'm running into a rendering/drilldown limitation and would appreciate guidance or confirmation if this is a known gap.
metadata.log_type = "ZSCALER_DNS"
additional.fields["dns_record_type"] = "A"
network.dns.questions.name = $request
network.dns.answers.data = $response
match:
$request
outcome:
$ips = array_distinct($response)
limit:
10000This groups results by $request (the queried domain) and aggregates all resolved IPs into a deduplicated array $ips.
Problem:
When $ips is displayed as a column in a Table widget, the array is rendered as a single comma-separated string in one cell, e.g.:
142.250.122.94, 142.251.106.94, 142.250.118.94
I configured a drilldown mapping on $ips pointing to the UDM field network.dns.answers.data (operator =). However, since the entire array is flattened into one string value per cell, clicking on it attempts to search for the full concatenated string as a single value — rather than letting me click an individual IP and drill down into just that value.
What I'm trying to achieve:
I want each IP address within the array to be individually clickable, triggering a drilldown search for network.dns.answers.data = <that specific IP> — while still keeping my match clause scoped to $request only (i.e., without exploding the aggregation at the query level by adding $response/network.dns.answers.data into the match block, which would change the grouping granularity of my results).
