<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help on eval command linked to a time input token in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582414#M11310</link>
    <description>&lt;P&gt;Add a change handler to the timepicker:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;      &amp;lt;change&amp;gt;
        &amp;lt;condition label="Last 30 days"&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;1&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;4&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition label="Last 7 days"&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;5&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;2&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;However, some of the labels don't equate to what you might expect. For example, "Last 7 days" from the presets ends up with a label of "Custom time" (at least in the version of Splunk I am using), but if you use relative 7 days ago to now snapped to start of day, you can get a label of "Last 7 days"&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jan 2022 16:28:06 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2022-01-25T16:28:06Z</dc:date>
    <item>
      <title>help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582285#M11301</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;as you can see in my xml, I use an eval command in order to define an health status&lt;/P&gt;&lt;P&gt;this eval command is linked to a token time&lt;/P&gt;&lt;P&gt;now I would like to correlate the rule of my eval command with the time token&lt;/P&gt;&lt;P&gt;For example, if I choose the "last 7 days" in my time token, the hang has to be &amp;gt; 5 and the crash &amp;gt; 2&lt;/P&gt;&lt;P&gt;But if i choose the "last 30 days" in my time token, the hang has to be &amp;gt; 1 and the crash &amp;gt; 4&lt;/P&gt;&lt;P&gt;how to do this please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;form theme="dark"&amp;gt;
  &amp;lt;search id="bib"&amp;gt;
    &amp;lt;query&amp;gt; index=toto ((sourcetype="hang") OR ( sourcetype="titi") 
    OR (sourcetype="tutu" web_app_duration_avg_ms &amp;amp;gt; 7000)) 
  &amp;lt;/query&amp;gt;
    &amp;lt;earliest&amp;gt;$date.earliest$&amp;lt;/earliest&amp;gt;
    &amp;lt;latest&amp;gt;$date.latest$&amp;lt;/latest&amp;gt;
  &amp;lt;/search&amp;gt;
    &amp;lt;input type="time" token="date" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;Période&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-7d@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search base="bib"&amp;gt;
          &amp;lt;query&amp;gt;| stats count(hang_process_name) as hang, count(crash_process_name) as crash by site 
| eval sante=if((hang&amp;amp;gt;5) AND (crash&amp;amp;gt;2), "Etat de santé dégradé","Etat de santé acceptable") 
&amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 16:23:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582285#M11301</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2022-01-25T16:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a token time</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582405#M11308</link>
      <description>&lt;P&gt;Is anybody can help please?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 15:09:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582405#M11308</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2022-01-25T15:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582414#M11310</link>
      <description>&lt;P&gt;Add a change handler to the timepicker:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;      &amp;lt;change&amp;gt;
        &amp;lt;condition label="Last 30 days"&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;1&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;4&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition label="Last 7 days"&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;5&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;2&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;However, some of the labels don't equate to what you might expect. For example, "Last 7 days" from the presets ends up with a label of "Custom time" (at least in the version of Splunk I am using), but if you use relative 7 days ago to now snapped to start of day, you can get a label of "Last 7 days"&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 16:28:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582414#M11310</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-25T16:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582483#M11321</link>
      <description>&lt;P&gt;sorry I dont understand to apply&lt;/P&gt;&lt;P&gt;what I have to modif in my eval command?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;SANTE&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="true" autoRun="true"&amp;gt;
    &amp;lt;input type="time" token="field1" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;sss&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
      
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=toto sourcetype=tutu
| stats count(hang_process_name) as hang, count(crash_process_name) as crash by site 
| eval sante=if((hang&amp;amp;gt;5) AND (crash&amp;amp;gt;2), "Etat de santé dégradé","Etat de santé acceptable")  
| eval severity=if(sante="Etat de santé dégradé",1,0) 
| rangemap field=severity low=0-0 default=severe&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="height"&amp;gt;50&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 07:17:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582483#M11321</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2022-01-26T07:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582487#M11323</link>
      <description>&lt;LI-CODE lang="markup"&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;SANTE&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="true" autoRun="true"&amp;gt;
    &amp;lt;input type="time" token="field1" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;sss&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;condition label="Last 30 days"&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;1&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;4&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition label="Last 7 days"&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;5&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;2&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition&amp;gt;&amp;lt;!-- Default values for these tokens --&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;1&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;1&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
      &amp;lt;/change&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=toto sourcetype=tutu
| stats count(hang_process_name) as hang, count(crash_process_name) as crash by site 
| eval sante=if((hang&amp;amp;gt;$hangmin$) AND (crash&amp;amp;gt;$crashmin$), "Etat de santé dégradé","Etat de santé acceptable")  
| eval severity=if(sante="Etat de santé dégradé",1,0) 
| rangemap field=severity low=0-0 default=severe&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="height"&amp;gt;50&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 26 Jan 2022 08:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582487#M11323</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-26T08:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582490#M11324</link>
      <description>&lt;P&gt;something is not working&lt;/P&gt;&lt;P&gt;for example, if I modify the condition for the last 7 days&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;  &amp;lt;condition label="Last 7 days"&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;50&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;4&amp;lt;/set&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;a site is considered as "Etat de santé dégradé" instead of "Etat de santé acceptable" because his results are under the threshold of hangmin and crashmin....&lt;/P&gt;&lt;P&gt;I dont understand what is wrong...&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 08:46:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582490#M11324</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2022-01-26T08:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582491#M11325</link>
      <description>&lt;P&gt;How have you selected Last 7 days?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 08:52:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582491#M11325</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-26T08:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582492#M11326</link>
      <description>&lt;P&gt;yes...&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 09:00:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582492#M11326</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2022-01-26T09:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582494#M11327</link>
      <description>&lt;P&gt;As I said earlier, this doesn't work, you need to use relative, not the preset&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ITWhisperer_0-1643187786140.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17675i93B96E118B14A2ED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ITWhisperer_0-1643187786140.png" alt="ITWhisperer_0-1643187786140.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 09:03:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582494#M11327</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-26T09:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582495#M11328</link>
      <description>&lt;P&gt;Yes I done it too&lt;/P&gt;&lt;P&gt;And no matter the hangmin and the crashmin I define the sante is always "Etat de santé dégradé" for this specific site...&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 09:10:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582495#M11328</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2022-01-26T09:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582496#M11329</link>
      <description>&lt;P&gt;Can you share your current SimpleXML?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 09:13:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582496#M11329</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-26T09:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582497#M11330</link>
      <description>&lt;P&gt;here is&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;SANTE&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="true" autoRun="true"&amp;gt;
    &amp;lt;input type="time" token="field1" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;sss&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;condition label="Last 30 days"&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;200&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;200&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition label="Last 7 days"&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;100&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;100&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition&amp;gt;
          &amp;lt;!-- Default values for these tokens --&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;1&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;1&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
      &amp;lt;/change&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;XXX&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=tutu sourcetype=toto
| stats count(hang_process_name) as hang, count(crash_process_name) as crash by site 
| eval sante=if((hang&amp;amp;gt;$hangmin$) AND (crash&amp;amp;gt;$crashmin$), "Etat de santé dégradé","Etat de santé acceptable") 
| eval severity=if(sante="Etat de santé dégradé",1,0) 
| rangemap field=severity low=0-0 default=severe 
| table site sante hang crash&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 26 Jan 2022 09:15:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582497#M11330</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2022-01-26T09:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582498#M11331</link>
      <description>&lt;LI-CODE lang="markup"&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;SANTE&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="true" autoRun="true"&amp;gt;
    &amp;lt;input type="time" token="field1" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;sss&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;condition label="Last 30 days"&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;200&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;200&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition label="Last 7 days"&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;100&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;100&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition&amp;gt;
          &amp;lt;!-- Default values for these tokens --&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;1&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;1&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
      &amp;lt;/change&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;XXX&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=toto 
| fields hang_process_name crash_process_name site 
| stats count(hang_process_name) as hang, count(crash_process_name) as crash by site 
| eval sante=if((hang&amp;amp;gt;$hangmin$) AND (crash&amp;amp;gt;$crashmin$), "Etat de santé dégradé","Etat de santé acceptable") 
| eval severity=if(sante="Etat de santé dégradé",1,0) 
| rangemap field=severity low=0-0 default=severe 
| table site sante hang crash&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 26 Jan 2022 09:21:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582498#M11331</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2022-01-26T09:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582502#M11332</link>
      <description>&lt;P&gt;I have found&lt;/P&gt;&lt;P&gt;Its due to the language...&lt;/P&gt;&lt;P&gt;If I replace "Last 7 days" by "Dernière 7 jours" it works&lt;/P&gt;&lt;P&gt;But it doesnt works for 30 j!&lt;/P&gt;&lt;P&gt;I dont understand&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 10:10:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582502#M11332</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2022-01-26T10:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582507#M11333</link>
      <description>&lt;P&gt;Try changing the label of the timepicker to show what the values of the token are&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;label&amp;gt;$hangmin$ $crashmin$&amp;lt;/label&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 26 Jan 2022 10:11:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582507#M11333</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-26T10:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582509#M11334</link>
      <description>&lt;P&gt;Change the title to investigate the value of the label&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;      &amp;lt;label&amp;gt;$pickerlabel$&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;condition label="Last 30 days"&amp;gt;
          &amp;lt;eval token="pickerlabel"&amp;gt;label&amp;lt;/eval&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;200&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;200&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition label="Last 7 days"&amp;gt;
          &amp;lt;eval token="pickerlabel"&amp;gt;label&amp;lt;/eval&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;100&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;100&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
        &amp;lt;condition&amp;gt;
          &amp;lt;!-- Default values for these tokens --&amp;gt;
          &amp;lt;eval token="pickerlabel"&amp;gt;label&amp;lt;/eval&amp;gt;
          &amp;lt;set token="hangmin"&amp;gt;1&amp;lt;/set&amp;gt;
          &amp;lt;set token="crashmin"&amp;gt;1&amp;lt;/set&amp;gt;
        &amp;lt;/condition&amp;gt;
      &amp;lt;/change&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 10:19:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582509#M11334</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-26T10:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582510#M11335</link>
      <description>&lt;P&gt;I know what the value are because I have added&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| table site sante hang crash&lt;/LI-CODE&gt;&lt;P&gt;so I can see the input time token is not working correctly&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 10:20:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582510#M11335</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2022-01-26T10:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: help on eval command linked to a time input token</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582512#M11336</link>
      <description>&lt;P&gt;This doesn't tell you the value of the tokens being used in your if statement - you need to debug the timepicker change handler to determine which values are being set in the tokens - I think there is a token debugger app in splunkbase that you could try if simply displaying them in labels doesn't work for you&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 10:27:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/help-on-eval-command-linked-to-a-time-input-token/m-p/582512#M11336</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-26T10:27:19Z</dc:date>
    </item>
  </channel>
</rss>

