<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to display date/Time range in Dashboard? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365391#M23868</link>
    <description>&lt;P&gt;i want display the date range in a dashboard.&lt;BR /&gt;please help me in doing this?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2891i295A02A34D9E2D6F/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jul 2022 13:27:43 GMT</pubDate>
    <dc:creator>sravankaripe</dc:creator>
    <dc:date>2022-07-25T13:27:43Z</dc:date>
    <item>
      <title>How to display date/Time range in Dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365391#M23868</link>
      <description>&lt;P&gt;i want display the date range in a dashboard.&lt;BR /&gt;please help me in doing this?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2891i295A02A34D9E2D6F/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 13:27:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365391#M23868</guid>
      <dc:creator>sravankaripe</dc:creator>
      <dc:date>2022-07-25T13:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365392#M23869</link>
      <description>&lt;P&gt;what is the purpose of the dashboard? in what context would you like to present that data?&lt;BR /&gt;
you can grab this data by searching the search log or audit log... and then present the results as you wish&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 15:32:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365392#M23869</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-05T15:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365393#M23870</link>
      <description>&lt;P&gt;i want to display earliest and latest time ranges in &lt;BR /&gt;
mm/dd/yy  hh:mm:ss format as a dynamic title to a panel &lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 17:12:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365393#M23870</guid>
      <dc:creator>sravankaripe</dc:creator>
      <dc:date>2017-05-05T17:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365394#M23871</link>
      <description>&lt;P&gt;so you want the panel to have the times according to the search that runs within the panel?&lt;BR /&gt;
how do you determine that time range? do you have a timepicker input?&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 17:18:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365394#M23871</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-05-05T17:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365395#M23872</link>
      <description>&lt;P&gt;Yes,i am using time  picker input&lt;BR /&gt;
field1.earliest&lt;BR /&gt;
field1.latest&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 17:21:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365395#M23872</guid>
      <dc:creator>sravankaripe</dc:creator>
      <dc:date>2017-05-05T17:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365396#M23873</link>
      <description>&lt;P&gt;try this&lt;/P&gt;

&lt;P&gt;earliest=-2d | stats last(_time) as earliest first(_time) as latest &lt;BR /&gt;
 | eval startDate=strftime(earliest, "%B %d %Y") &lt;BR /&gt;
 | eval endDate=strftime(latest, "%B %d %Y") &lt;BR /&gt;
 | eval reportstring = "Report: ".startDate."-".endDate&lt;BR /&gt;
 | fields reportstring&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:58:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365396#M23873</guid>
      <dc:creator>SplunkersRock</dc:creator>
      <dc:date>2020-09-29T13:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365397#M23874</link>
      <description>&lt;P&gt;| stats last(_time) as earliest first(_time) as latest &lt;BR /&gt;
 | eval startDate=strftime(earliest, "%B-%d-%Y %H:%M:%S") &lt;BR /&gt;
 | eval endDate=strftime(latest, "%B-%d-%Y %H:%M:%S") &lt;BR /&gt;
 | eval reportstring = "Report  From: ".startDate."  To  ".endDate&lt;BR /&gt;
 | fields reportstring&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:58:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365397#M23874</guid>
      <dc:creator>SplunkersRock</dc:creator>
      <dc:date>2020-09-29T13:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365398#M23875</link>
      <description>&lt;P&gt;My slight variation on the answer by @SplunkersRock...&lt;/P&gt;

&lt;P&gt;In my dashboards, I typically use a base search to generate a bunch of fields that I use across multiple visualizations (I've removed an initial stage and a bunch of fields from this example). I generate the basic time range values in that base search, then use a more specific search to format those values:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;search id="base_metrics"&amp;gt;
  &amp;lt;query&amp;gt;stats count earliest(_time) as earliest, latest(_time) as latest&amp;lt;/query&amp;gt;
  &amp;lt;earliest&amp;gt;$earliest$&amp;lt;/earliest&amp;gt;
  &amp;lt;latest&amp;gt;$latest$&amp;lt;/latest&amp;gt;
&amp;lt;/search&amp;gt;
&amp;lt;search base="base_metrics"&amp;gt;
  &amp;lt;query&amp;gt;eval startTime=strftime(earliest, "%x %H:%M:%S") | eval endTime=if(strftime(earliest, "%x")=strftime(latest, "%x"), strftime(latest, "%H:%M:%S"), strftime(latest, "%x %H:%M:%S")) | eval diff=(latest-earliest) | eval hours=floor(diff/3600) | eval minutes=floor((diff-(hours*3600))/60) | eval seconds=floor(diff-(hours*3600)-(minutes*60)) | eval duration=hours." hour".if(hours&amp;amp;gt;1,"s "," ").minutes." minute".if(minutes&amp;amp;gt;1,"s "," ").seconds." second".if(seconds&amp;amp;gt;1,"s","")
  &amp;lt;progress&amp;gt;
   &amp;lt;condition match="'job.resultCount' &amp;gt; 0"&amp;gt;
    &amp;lt;set token="startTime"&amp;gt;$result.startTime$&amp;lt;/set&amp;gt;
    &amp;lt;set token="endTime"&amp;gt;$result.endTime$&amp;lt;/set&amp;gt;
    &amp;lt;set token="duration"&amp;gt;$result.duration$&amp;lt;/set&amp;gt;
    &amp;lt;set token="eventCount"&amp;gt;$result.count$&amp;lt;/set&amp;gt;
   &amp;lt;/condition&amp;gt;
   &amp;lt;condition&amp;gt;
     &amp;lt;unset token="startTime"&amp;gt;&amp;lt;/unset&amp;gt;
     &amp;lt;unset token="endTime"&amp;gt;&amp;lt;/unset&amp;gt;
     &amp;lt;unset token="duration"&amp;gt;&amp;lt;/unset&amp;gt;
     &amp;lt;unset token="eventCount"&amp;gt;&amp;lt;/unset&amp;gt;
   &amp;lt;/condition&amp;gt;
  &amp;lt;/progress&amp;gt;
&amp;lt;/search&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I then use those tokens in an HTML panel (I have chosen to embed this panel in the dashboard &lt;CODE&gt;&amp;lt;fieldset&amp;gt;&lt;/CODE&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;html depends="$eventCount$,$duration$,$startTime$,$endTime$"&amp;gt;
  $eventCount$ events spanning $duration$ ($startTime$ to $endTime$)
&amp;lt;/html&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Example output:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;114983 events spanning 1 hour 10 minutes 57 seconds (8/14/17 06:09:54 - 07:20:51)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The faffing around with &lt;CODE&gt;if&lt;/CODE&gt;, &lt;CODE&gt;eval&lt;/CODE&gt;, and &lt;CODE&gt;strftime&lt;/CODE&gt; in the query is an evolving work-in-progress to generate concise, readable output. For example, if the start and end times have the same date, omit the end date.&lt;/P&gt;

&lt;P&gt;Feedback, suggestions welcome.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 08:45:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365398#M23875</guid>
      <dc:creator>Graham_Hanningt</dc:creator>
      <dc:date>2017-09-06T08:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365399#M23876</link>
      <description>&lt;P&gt;This has definitely been answered before. What you need to do is to introduce a dummy search with your time input tokens to get the Earliest and Latest time based on time input selection through predefined search job tokens i.e. &lt;CODE&gt;$job.earliestTime$&lt;/CODE&gt; and &lt;CODE&gt;$job.latestTime$&lt;/CODE&gt;. PS: I have used &lt;CODE&gt;&amp;lt;done&amp;gt;&lt;/CODE&gt; search event handler.&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2889i8DC9E0DC4AC3EF82/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Following is a sample run anywhere dashboard for the attached image:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;Show Time from Time Picker&amp;lt;/label&amp;gt;
  &amp;lt;!-- Dummy search to pull selected time range earliest and latest date/time --&amp;gt;
  &amp;lt;search&amp;gt;
    &amp;lt;query&amp;gt;| makeresults&amp;lt;/query&amp;gt;
    &amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;
    &amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;
    &amp;lt;done&amp;gt;
      &amp;lt;eval token="tokTime"&amp;gt;$job.earliestTime$&amp;lt;/eval&amp;gt;
      &amp;lt;eval token="tokEarliestTime"&amp;gt;strftime(strptime($job.earliestTime$,"%Y/%m/%dT%H:%M:%S.%3N %p"),"%m/%d/%y %I:%M:%S.%3N %p")&amp;lt;/eval&amp;gt;
      &amp;lt;eval token="tokLatestTime"&amp;gt;strftime(strptime($job.latestTime$,"%Y/%m/%dT%H:%M:%S.%3N %p"),"%m/%d/%y %I:%M:%S.%3N %p")&amp;lt;/eval&amp;gt;
    &amp;lt;/done&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;
    &amp;lt;input type="time" token="field1"&amp;gt;
      &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;!-- sample HTML Panel to display results in required format --&amp;gt;
      &amp;lt;html&amp;gt;
        ( $tokEarliestTime$ to $tokLatestTime$ )
      &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:32:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365399#M23876</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-09-08T07:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365400#M23877</link>
      <description>&lt;P&gt;@sravankaripe, you need to use &lt;CODE&gt;hideTitle="true"&lt;/CODE&gt; to hide Splunk's default dashboard title and then use HTML Panel to create your own title. You can display time using the option in my answer below.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2017 04:38:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365400#M23877</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-09-14T04:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365401#M23878</link>
      <description>&lt;P&gt;How to display this on the scheduled PDF? Its not generating in the scheduled PDF &lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 22:43:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365401#M23878</guid>
      <dc:creator>arayapati83</dc:creator>
      <dc:date>2018-03-09T22:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365402#M23879</link>
      <description>&lt;P&gt;@arayapati83, if you are trying this for Scheduled Dashboard then you have to make sure that is it not a form with inputs (i.e. root node of the view should be &lt;CODE&gt;&amp;lt;dashboard&amp;gt;&lt;/CODE&gt; not &lt;CODE&gt;&amp;lt;form&amp;gt;&lt;/CODE&gt;).  Refer to the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Viz/DashboardPDFs#Limitations_to_PDF_generation"&gt;limitations of PDF Delivery of Dashboards in Splunk&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;I tried the following and it worked fine for me:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;gooScheduled PDF with timestamp&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Report runtime from $tokEarliestTime$ to $tokLatestTime$&amp;lt;/title&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal sourcetype=splunkd log_level!=INFO component=*
| timechart count by component limit=5 useother=f usenull=f&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-1d@d&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;-0d@d&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
          &amp;lt;done&amp;gt;
            &amp;lt;eval token="tokEarliestTime"&amp;gt;strftime(strptime($job.earliestTime$,"%Y/%m/%dT%H:%M:%S.%3N %p"),"%m/%d/%y %I:%M:%S.%3N %p")&amp;lt;/eval&amp;gt;
            &amp;lt;eval token="tokLatestTime"&amp;gt;strftime(strptime($job.latestTime$,"%Y/%m/%dT%H:%M:%S.%3N %p"),"%m/%d/%y %I:%M:%S.%3N %p")&amp;lt;/eval&amp;gt;
          &amp;lt;/done&amp;gt;          
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.overflowMode"&amp;gt;ellipsisNone&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.rotation"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisX.abbreviation"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisX.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY.abbreviation"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY2.abbreviation"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY2.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart"&amp;gt;area&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.bubbleMaximumSize"&amp;gt;50&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.bubbleMinimumSize"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.bubbleSizeBy"&amp;gt;area&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;gaps&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.showDataLabels"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.sliceCollapsingThreshold"&amp;gt;0.01&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.stackMode"&amp;gt;default&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.style"&amp;gt;shiny&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.layout.splitSeries"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.layout.splitSeries.allowIndependentYRanges"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.legend.labelStyle.overflowMode"&amp;gt;ellipsisMiddle&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.legend.mode"&amp;gt;standard&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.legend.placement"&amp;gt;right&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.lineWidth"&amp;gt;2&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.scales.shared"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.size"&amp;gt;medium&amp;lt;/option&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 10 Mar 2018 17:02:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365402#M23879</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-03-10T17:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365403#M23880</link>
      <description>&lt;P&gt;@niketnilay I copy pasted your code above into a dashboard and tried generating PDF. Even there I get Report runtime from $tokEarliestTime$ to $tokLatestTime$ .In the pdf the tokens are not getting resolved during runtime. &lt;/P&gt;

&lt;P&gt;I had to remove some options in the above code as I got validation errors.. Could it be a different version of SPLUNK? we are using Splunk Version 6.5.3.1. Also tried on Splunk Version ............................................7.0.2 . Even there I didn't have to remove any options but the PDF generated didn't resolve the tokens&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 18:51:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365403#M23880</guid>
      <dc:creator>arayapati83</dc:creator>
      <dc:date>2018-03-12T18:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365404#M23881</link>
      <description>&lt;P&gt;@arayapati83, yes I had created dashboard in Splunk 7.0.2 which has Trellis option (although I have not used). Trellis was not available in Splunk 6.5, as it was introduced in 6.6&lt;/P&gt;

&lt;P&gt;I have not tested Scheduled PDF, but &lt;CODE&gt;Export --&amp;gt; Export PDF&lt;/CODE&gt; option works fine for me (refer to screenshot attached). Could you please test Export PDF and confirm?&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://wiki.splunk.com/images/1/18/Dashboard_PDF.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 19:45:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365404#M23881</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-03-12T19:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365405#M23882</link>
      <description>&lt;P&gt;@niketnilay export PDF shows fine, its the scheduled PDF that's the problem&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 21:59:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365405#M23882</guid>
      <dc:creator>arayapati83</dc:creator>
      <dc:date>2018-03-12T21:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365406#M23883</link>
      <description>&lt;P&gt;@arayapati83, if you have valid &lt;CODE&gt;Splunk Entitlement&lt;/CODE&gt; report this to &lt;CODE&gt;Splunk Support&lt;/CODE&gt;. Since the original question here is on similar output but a different topic, please create a new question for &lt;CODE&gt;Tokens working in Export PDF but not working in Scheduled PDF&lt;/CODE&gt; with &lt;CODE&gt;BUG&lt;/CODE&gt; tag.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 01:48:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/365406#M23883</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-03-13T01:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/606779#M49801</link>
      <description>&lt;DIV class=""&gt;If you want to display the &lt;EM&gt;&lt;STRONG&gt;chosen date/time&lt;/STRONG&gt;&lt;/EM&gt; instead of the job's date/time range (in a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;classic dashboard&lt;/I&gt;&lt;SPAN&gt;) even if you selected "last 15 minutes" instead of an exact date/time, you can do this as follows:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Add a&amp;nbsp;&lt;FONT color="#800080"&gt;&lt;EM&gt;change&lt;/EM&gt;&lt;/FONT&gt; event to your time&amp;nbsp;input which sets a token named&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;FONT color="#800080"&gt;timeRange&lt;/FONT&gt;&lt;/EM&gt;.&lt;BR /&gt;You can calculate the actual start and end date/time as follows, then format it as you need:&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;  &amp;lt;fieldset submitButton="false" autoRun="false"&amp;gt;
    &amp;lt;input type="time" token="timeRange" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;Date Time Range&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-1h@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;@h&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
      &amp;lt;change&amp;gt;
        &amp;lt;eval token="timeRangeEarliest"&amp;gt;if(isnum($timeRange.earliest$), $timeRange.earliest$, relative_time(now(), $timeRange.earliest$))&amp;lt;/eval&amp;gt;
        &amp;lt;eval token="timeRangeLatest"&amp;gt;if(isnum($timeRange.latest$), $timeRange.latest$, relative_time(now(), $timeRange.latest$))&amp;lt;/eval&amp;gt;
        &amp;lt;eval token="prettyPrinttimeRangeFromTime"&amp;gt;strftime($timeRangeEarliest$, "%a, %e %b %Y %T.%3N")&amp;lt;/eval&amp;gt;
        &amp;lt;eval token="prettyPrinttimeRangeToTime"&amp;gt;strftime($timeRangeLatest$, "%a, %e %b %Y %T.%3N")&amp;lt;/eval&amp;gt;
      &amp;lt;/change&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;time&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;input has a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;default&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;earliest&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;FONT color="#800080"&gt;-1h@h&lt;/FONT&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;latest&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;FONT color="#800080"&gt;@h&lt;/FONT&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(an hour ago until now to the hour).&lt;/LI&gt;&lt;LI&gt;On change, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;FONT color="#800080"&gt;timeRangeEarliest&lt;/FONT&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;FONT color="#800080"&gt;timeRangeLatest&lt;/FONT&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tokens are set as either “the chosen exact date/time” &lt;EM&gt;&lt;U&gt;or&lt;/U&gt;&lt;/EM&gt; “calculated relative to the chosen range”.&lt;/LI&gt;&lt;LI&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#800080"&gt;&lt;EM&gt;timeRangeEarliest&lt;/EM&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#800080"&gt;&lt;EM&gt;timeRangeLatest&lt;/EM&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tokens are then formatted as a string using&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;FONT color="#800080"&gt;strftime&lt;/FONT&gt;&lt;/EM&gt;.&lt;BR /&gt;See date and time formatting&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://docs.splunk.com/Documentation/SCS/current/Search/Timevariables" target="_blank" rel="noopener noreferrer"&gt;here&lt;/A&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;DIV class=""&gt;You can now display the date/time in an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#800080"&gt;&lt;EM&gt;html&lt;/EM&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;block e.g.&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;html&amp;gt;
        &amp;lt;h3&amp;gt;Date/Time Range&amp;lt;/h3&amp;gt;
        &amp;lt;table&amp;gt;
          &amp;lt;tr&amp;gt;
            &amp;lt;td&amp;gt;From:&amp;lt;/td&amp;gt;
            &amp;lt;td&amp;gt;$prettyPrinttimeRangeFromTime$&amp;lt;/td&amp;gt;
          &amp;lt;/tr&amp;gt;
          &amp;lt;tr&amp;gt;
            &amp;lt;td&amp;gt;To:&amp;lt;/td&amp;gt;
            &amp;lt;td&amp;gt;$prettyPrinttimeRangeToTime$&amp;lt;/td&amp;gt;
          &amp;lt;/tr&amp;gt;
        &amp;lt;/table&amp;gt;
      &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 00:48:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/606779#M49801</guid>
      <dc:creator>cslang</dc:creator>
      <dc:date>2022-07-25T00:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: Display date/Time range in Dashbaord</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/647664#M52972</link>
      <description>&lt;P&gt;I found that the above solution works for all time picker options except the Date Range option. This consistently displays an earlier date than the day chosen.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 18:44:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-display-date-Time-range-in-Dashboard/m-p/647664#M52972</guid>
      <dc:creator>RedPooka</dc:creator>
      <dc:date>2023-06-20T18:44:53Z</dc:date>
    </item>
  </channel>
</rss>

