<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is chain search not inheriting value from time range token? in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-chain-search-not-inheriting-value-from-time-range-token/m-p/607100#M1685</link>
    <description>&lt;DIV class=""&gt;Hello,&lt;/DIV&gt;
&lt;DIV class=""&gt;I am using dashboard studio on&amp;nbsp;Splunk Cloud - 8.2.2203.2 where I have a base search and 2 chained searches that reference the base search. The base search is using the&amp;nbsp;&lt;STRONG&gt;Global Time Range (global_time)&amp;nbsp;&lt;/STRONG&gt;as a time range input when searching. The chain searches should also inherent the same value that the base search is getting from&amp;nbsp;&lt;STRONG&gt;global_time&lt;/STRONG&gt; as shown below.&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;"Time Range&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;
&lt;DIV&gt;Currently using&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Global Time Range&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;input&lt;/DIV&gt;
&lt;DIV class=""&gt;$global_time.earliest$ - $global_time.latest$"&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;However, when I am changing the time input, the panel that is using one of the chain search does not load automatically and would only work if I refresh the entire page. In addition, when I click on the magnifying glass (Open in search) for the panel, it takes me to a search page but does not return any results because of the error "Invalid earliest_time". I then manually select "Last 24 hours" for the time range in the search query drop down button and that resolve the error and returned results. This tells me that the search query itself is good but there may have been issue with the time range value not being passed from the base search to the chain search. If my panel is referencing a base search directly, the time range value works perfectly, the dashboard re-search when I change the time, and have no error when I click "Open in Search".&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;I also noted that in the URL after I click "Open in Search" for the panel that is using a chain search, it had this in the URL: "earliest=%24&lt;STRONG&gt;global_time.earliest&lt;/STRONG&gt;%24&amp;amp;latest=%24&lt;STRONG&gt;global_time.latest&lt;/STRONG&gt;%24". This tells me that the value that &lt;STRONG&gt;global_time&amp;nbsp;&lt;/STRONG&gt;was holding did not get pass onto the chain search. I confirmed this by manually selecting the&amp;nbsp;"Last 24 hours" for the time range in the search query drop down button and noted this in the URL: "earliest=-24h%40h&amp;amp;latest=now", something along this line should have been in the URL when I click "Open in Search" instead of variable name.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;Can someone please help to see if this is a bug or is there something special that needs to be configured for a chain search to inherent value from a time range token?&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;Thank you&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Wed, 27 Jul 2022 14:01:59 GMT</pubDate>
    <dc:creator>nttran</dc:creator>
    <dc:date>2022-07-27T14:01:59Z</dc:date>
    <item>
      <title>Why is chain search not inheriting value from time range token?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-chain-search-not-inheriting-value-from-time-range-token/m-p/607100#M1685</link>
      <description>&lt;DIV class=""&gt;Hello,&lt;/DIV&gt;
&lt;DIV class=""&gt;I am using dashboard studio on&amp;nbsp;Splunk Cloud - 8.2.2203.2 where I have a base search and 2 chained searches that reference the base search. The base search is using the&amp;nbsp;&lt;STRONG&gt;Global Time Range (global_time)&amp;nbsp;&lt;/STRONG&gt;as a time range input when searching. The chain searches should also inherent the same value that the base search is getting from&amp;nbsp;&lt;STRONG&gt;global_time&lt;/STRONG&gt; as shown below.&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;"Time Range&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV&gt;
&lt;DIV&gt;Currently using&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Global Time Range&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;input&lt;/DIV&gt;
&lt;DIV class=""&gt;$global_time.earliest$ - $global_time.latest$"&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;However, when I am changing the time input, the panel that is using one of the chain search does not load automatically and would only work if I refresh the entire page. In addition, when I click on the magnifying glass (Open in search) for the panel, it takes me to a search page but does not return any results because of the error "Invalid earliest_time". I then manually select "Last 24 hours" for the time range in the search query drop down button and that resolve the error and returned results. This tells me that the search query itself is good but there may have been issue with the time range value not being passed from the base search to the chain search. If my panel is referencing a base search directly, the time range value works perfectly, the dashboard re-search when I change the time, and have no error when I click "Open in Search".&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;I also noted that in the URL after I click "Open in Search" for the panel that is using a chain search, it had this in the URL: "earliest=%24&lt;STRONG&gt;global_time.earliest&lt;/STRONG&gt;%24&amp;amp;latest=%24&lt;STRONG&gt;global_time.latest&lt;/STRONG&gt;%24". This tells me that the value that &lt;STRONG&gt;global_time&amp;nbsp;&lt;/STRONG&gt;was holding did not get pass onto the chain search. I confirmed this by manually selecting the&amp;nbsp;"Last 24 hours" for the time range in the search query drop down button and noted this in the URL: "earliest=-24h%40h&amp;amp;latest=now", something along this line should have been in the URL when I click "Open in Search" instead of variable name.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;Can someone please help to see if this is a bug or is there something special that needs to be configured for a chain search to inherent value from a time range token?&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;Thank you&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 27 Jul 2022 14:01:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-chain-search-not-inheriting-value-from-time-range-token/m-p/607100#M1685</guid>
      <dc:creator>nttran</dc:creator>
      <dc:date>2022-07-27T14:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: Why is chain search not inheriting value from time range token?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-chain-search-not-inheriting-value-from-time-range-token/m-p/612325#M1761</link>
      <description>&lt;P&gt;Experiencing the same issue on Splunk Enterprise 9.0.0 with the "Open in Search" for panels using chain searches.&lt;/P&gt;&lt;P&gt;Changing the time input seems to work fine for panels using chain searches, though.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 21:47:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-chain-search-not-inheriting-value-from-time-range-token/m-p/612325#M1761</guid>
      <dc:creator>kristenqw</dc:creator>
      <dc:date>2022-09-07T21:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why is chain search not inheriting value from time range token?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-chain-search-not-inheriting-value-from-time-range-token/m-p/623535#M1939</link>
      <description>&lt;P&gt;We also stumbled across this bug in Splunk Enterprise 9.0.2.&lt;/P&gt;&lt;P&gt;Has anyone found a solution yet or opened a case for this?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2022 07:53:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-chain-search-not-inheriting-value-from-time-range-token/m-p/623535#M1939</guid>
      <dc:creator>DATEVeG</dc:creator>
      <dc:date>2022-12-07T07:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why is chain search not inheriting value from time range token?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-chain-search-not-inheriting-value-from-time-range-token/m-p/677016#M2823</link>
      <description>&lt;P&gt;I can confirm this is still on issue.&lt;/P&gt;&lt;P&gt;Version:9.0.2303.202&lt;/P&gt;&lt;P&gt;Build:06d6be78fc0e&lt;/P&gt;&lt;P&gt;Setting the Base Search to use the global time selector's token and verifying the chain searches are using the same token is not sufficient in getting the time selector to update the panels.&amp;nbsp; they just stay frozen when changing the time selector.&amp;nbsp; Dashboards cannot be optimized properly if we cannot use base searches.&lt;/P&gt;&lt;P&gt;i cannot take over the world with this bug in place.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 22:43:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-chain-search-not-inheriting-value-from-time-range-token/m-p/677016#M2823</guid>
      <dc:creator>weidertc</dc:creator>
      <dc:date>2024-02-08T22:43:52Z</dc:date>
    </item>
  </channel>
</rss>

