Skip to main content
Question

[Google SecOps Dashboards] Drilldown Not Working on Individual Array Elements

  • October 10, 2026
  • 0 replies
  • 5 views

spartan_07
Forum|alt.badge.img+2

I'm trying to configure drilldown functionality on a Table widget in Google SecOps Dashboards, where one of the displayed fields is an array (repeated field). I'm running into a rendering/drilldown limitation and would appreciate guidance or confirmation if this is a known gap.

metadata.log_type = "ZSCALER_DNS"
additional.fields["dns_record_type"] = "A"
network.dns.questions.name = $request
network.dns.answers.data = $response

match:
$request

outcome:
$ips = array_distinct($response)

limit:
10000

This groups results by $request (the queried domain) and aggregates all resolved IPs into a deduplicated array $ips.

Problem:

When $ips is displayed as a column in a Table widget, the array is rendered as a single comma-separated string in one cell, e.g.:

142.250.122.94, 142.251.106.94, 142.250.118.94

 

I configured a drilldown mapping on $ips pointing to the UDM field network.dns.answers.data (operator =). However, since the entire array is flattened into one string value per cell, clicking on it attempts to search for the full concatenated string as a single value — rather than letting me click an individual IP and drill down into just that value.



What I'm trying to achieve:

I want each IP address within the array to be individually clickable, triggering a drilldown search for network.dns.answers.data = <that specific IP> — while still keeping my match clause scoped to $request only (i.e., without exploding the aggregation at the query level by adding $response/network.dns.answers.data into the match block, which would change the grouping granularity of my results).