<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change search query according to time in dashboard? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500167#M32747</link>
    <description>&lt;P&gt;Try my answer.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Apr 2020 13:52:30 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2020-04-01T13:52:30Z</dc:date>
    <item>
      <title>Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500153#M32733</link>
      <description>&lt;P&gt;I want to change my search query according to the time of the day&lt;BR /&gt;
   &lt;CODE&gt;&lt;BR /&gt;
             &amp;lt;query&amp;gt;index=--- application=------ |search abc=1&lt;BR /&gt;
              &amp;lt;/query&amp;gt;&lt;BR /&gt;
&lt;/CODE&gt;&lt;BR /&gt;
So in my dashboard I want the query to change acc to the time of the day. Like for example &lt;BR /&gt;
from 12:00am to 1:30am &lt;BR /&gt;
|search abc=1&lt;BR /&gt;
from 1:30am to3:00am&lt;BR /&gt;
|search abc=2&lt;BR /&gt;
&amp;amp; so on&lt;BR /&gt;
Please help guys!!!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 10:57:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500153#M32733</guid>
      <dc:creator>gurkiratsingh</dc:creator>
      <dc:date>2020-03-25T10:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500154#M32734</link>
      <description>&lt;P&gt;with a dropdown or set of radio buttons, this would be pretty straightforward&lt;/P&gt;

&lt;P&gt;are you wanting the search to "automagic itself", or to have user-selectable options?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 15:42:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500154#M32734</guid>
      <dc:creator>wmyersas</dc:creator>
      <dc:date>2020-03-25T15:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500155#M32735</link>
      <description>&lt;P&gt;Hi I want it to change automatically with no use of dropdown &amp;amp; no user selectable option.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 05:13:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500155#M32735</guid>
      <dc:creator>gurkiratsingh</dc:creator>
      <dc:date>2020-03-26T05:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500156#M32736</link>
      <description>&lt;P&gt;Based on you wanting this to Just Work™, take a look at using a &lt;CODE&gt;case()&lt;/CODE&gt; statement.&lt;/P&gt;

&lt;P&gt;Here's a sample with the two ranges done:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults
| eval h=strftime(_time,"%H"), mr=strftime(_time,"%m")
| eval filter=case((h=16 OR (h=17 AND m&amp;lt;31)),"1",(h=18 OR (h=17 AND m&amp;gt;30)),"2",1=1,"you forgot to fill-in a range")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This breaks down as the following:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;if the hour is 16 (4p), or it's 17 (5p) &lt;EM&gt;and&lt;/EM&gt; less than or equal to half-past, return 1&lt;/LI&gt;
&lt;LI&gt;if the hour is 18 (6p), or it's 17 (5p) &lt;EM&gt;and&lt;/EM&gt; after half-past, return 2&lt;/LI&gt;
&lt;LI&gt;the &lt;CODE&gt;1=1...&lt;/CODE&gt; segment is the default case: ie, if you missed a range, you'll get the 'error message'&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Once you calculate your &lt;CODE&gt;filter&lt;/CODE&gt;, use it in your sample search thusly:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;search&amp;gt;
| &amp;lt;filter logic using case statement&amp;gt;
| where like(abc,'filter')
&amp;lt;rest of search&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Adjust and extend as desired&lt;/P&gt;

&lt;H4&gt;edited to change from &lt;CODE&gt;| search abc='filter'&lt;/CODE&gt; to &lt;CODE&gt;| where like(abc,'filter')&lt;/CODE&gt;&lt;/H4&gt;</description>
      <pubDate>Thu, 26 Mar 2020 16:40:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500156#M32736</guid>
      <dc:creator>wmyersas</dc:creator>
      <dc:date>2020-03-26T16:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500157#M32737</link>
      <description>&lt;P&gt;Hi I made the case expression as you told but when I am using it in a search it is showing no result found. Can the Returned Value From a Case Function be used in a Search? The case function that I made is working fine.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 11:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500157#M32737</guid>
      <dc:creator>gurkiratsingh</dc:creator>
      <dc:date>2020-03-30T11:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500158#M32738</link>
      <description>&lt;P&gt;"Can the Returned Value From a Case Function be used in a Search"&lt;/P&gt;

&lt;P&gt;Sure - so long as it's something in your data: that was why I used the example line of &lt;CODE&gt;| search abc='filter'&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Whatever the &lt;CODE&gt;case()&lt;/CODE&gt; returns goes in the field name you've given (in my example, it's &lt;CODE&gt;filter&lt;/CODE&gt;)&lt;/P&gt;

&lt;P&gt;You then use &lt;EM&gt;single quotes&lt;/EM&gt; around it when searching, so you get the &lt;EM&gt;value&lt;/EM&gt; of the field, and not the literal text of whatever you've named the field (eg "filter")&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 12:38:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500158#M32738</guid>
      <dc:creator>wmyersas</dc:creator>
      <dc:date>2020-03-30T12:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500159#M32739</link>
      <description>&lt;P&gt;Hi even on doing the above mentioned still I am not getting any result. The case function is working perfectly fine. For example when I am doing (|search abc=7) I am getting the results but when I use it through the case function (|search abc='filter') then I am not getting any results.  The value of filter is getting extracted correctly.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 05:32:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500159#M32739</guid>
      <dc:creator>gurkiratsingh</dc:creator>
      <dc:date>2020-03-31T05:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500160#M32740</link>
      <description>&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval hourmin=strftime(now(), "%H%M")
| eval ABC=case(
   hourmin&amp;lt;= 130, "1"
   hourmin&amp;lt;= 330, "2"
   hourmin&amp;lt;= 530, "3",
   true(), "4")
| where abc=ABC
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 31 Mar 2020 06:13:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500160#M32740</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-03-31T06:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500161#M32741</link>
      <description>&lt;P&gt;Hi I tried using where but still I am not getting any results.The value from the CASE is getting extracted correctly and when I use ( |search abc=7) then the results are coming but not when I use ( |search abc='filter) or (|search abc=filter) or (|where abc='filter') or (|where abc=filter).&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 07:13:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500161#M32741</guid>
      <dc:creator>gurkiratsingh</dc:creator>
      <dc:date>2020-03-31T07:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500162#M32742</link>
      <description>&lt;P&gt;That won't work because you have a colon in the time formatting&lt;/P&gt;

&lt;P&gt;And %H gives you the hour with leading 0 in 24hr format (eg 01 vs 13)&lt;/P&gt;

&lt;P&gt;but this does:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval when=tonumber(ltrim(strftime(now(),"%H%M"),"0"))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;(&lt;CODE&gt;tonumber()&lt;/CODE&gt; may not be required)&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 13:11:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500162#M32742</guid>
      <dc:creator>wmyersas</dc:creator>
      <dc:date>2020-03-31T13:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500163#M32743</link>
      <description>&lt;P&gt;try &lt;CODE&gt;| where like(abc,'filter')&lt;/CODE&gt; instead of &lt;CODE&gt;| search abc='filter'&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;(I updated my answer, too)&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 13:19:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500163#M32743</guid>
      <dc:creator>wmyersas</dc:creator>
      <dc:date>2020-03-31T13:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500164#M32744</link>
      <description>&lt;P&gt;You are correct about the colon; I updated my answer.  Leading zeroes make no difference and are fine.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 13:21:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500164#M32744</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-03-31T13:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500165#M32745</link>
      <description>&lt;P&gt;Hi this works perfectly now. Thanks a lot :-)) Btw can you also help me on another thing:&lt;BR /&gt;
(&lt;A href="https://answers.splunk.com/answers/810952/how-to-set-time-to-search.html"&gt;https://answers.splunk.com/answers/810952/how-to-set-time-to-search.html&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 06:44:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500165#M32745</guid>
      <dc:creator>gurkiratsingh</dc:creator>
      <dc:date>2020-04-01T06:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500166#M32746</link>
      <description>&lt;P&gt;Hi this has worked correctly but now I need to do another thing. Suppose abc is a message string which contains certain numbers acc to the current time. For example:&lt;BR /&gt;
 Filename : (*****&lt;STRONG&gt;&lt;EM&gt;0000&lt;/EM&gt;&lt;/STRONG&gt;**&lt;EM&gt;)&lt;BR /&gt;&lt;BR /&gt;
|eval filter=case(&lt;BR /&gt;
(  (IST_time_hour=23 AND IST_time_min &amp;gt;= 00) OR (IST_time_hour=00 AND IST_time_min &amp;lt;30) ),0000&lt;BR /&gt;
,( (IST_time_hour=00 AND IST_time_min &amp;gt;= 30) OR (IST_time_hour=01 AND IST_time_min &amp;lt;59) ),0130&lt;BR /&gt;
,( (IST_time_hour=02 AND IST_time_min &amp;gt;= 00) OR (IST_time_hour=03 AND IST_time_min &amp;lt;30) ),0300&lt;BR /&gt;
,( (IST_time_hour=03 AND IST_time_min &amp;gt;= 30) OR (IST_time_hour=04 AND IST_time_min &amp;lt;59) ),0430&lt;BR /&gt;
,( (IST_time_hour=05 AND IST_time_min &amp;gt;= 00) OR (IST_time_hour=06 AND IST_time_min &amp;lt;30) ),0600&lt;BR /&gt;
,( (IST_time_hour=06 AND IST_time_min &amp;gt;= 30) OR (IST_time_hour=07 AND IST_time_min &amp;lt;59) ),0730&lt;BR /&gt;
,( (IST_time_hour=08 AND IST_time_min &amp;gt;= 00) OR (IST_time_hour=09 AND IST_time_min &amp;lt;30) ),0900&lt;BR /&gt;
,( (IST_time_hour=09 AND IST_time_min &amp;gt;= 30) OR (IST_time_hour=10 AND IST_time_min &amp;lt;59) ),1030&lt;BR /&gt;
,( (IST_time_hour=11 AND IST_time_min &amp;gt;= 00) OR (IST_time_hour=12 AND IST_time_min &amp;lt;30) ),1200&lt;BR /&gt;
,( (IST_time_hour=12 AND IST_time_min &amp;gt;= 30) OR (IST_time_hour=13 AND IST_time_min &amp;lt;59) ),1330&lt;BR /&gt;
,( (IST_time_hour=14 AND IST_time_min &amp;gt;= 00) OR (IST_time_hour=15 AND IST_time_min &amp;lt;30) ),1500&lt;BR /&gt;
,( (IST_time_hour=15 AND IST_time_min &amp;gt;= 30) OR (IST_time_hour=16 AND IST_time_min &amp;lt;59) ),1630&lt;BR /&gt;
,( (IST_time_hour=17 AND IST_time_min &amp;gt;= 00) OR (IST_time_hour=18 AND IST_time_min &amp;lt;30) ),1800&lt;BR /&gt;
,( (IST_time_hour=18 AND IST_time_min &amp;gt;= 30) OR (IST_time_hour=19 AND IST_time_min &amp;lt;59) ),1930&lt;BR /&gt;
,( (IST_time_hour=20 AND IST_time_min &amp;gt;= 00) OR (IST_time_hour=21 AND IST_time_min &amp;lt;30) ),2100&lt;BR /&gt;
,( (IST_time_hour=21 AND IST_time_min &amp;gt;= 30) OR (IST_time_hour=22 AND IST_time_min &amp;lt;59) ),2230&lt;BR /&gt;
)&lt;BR /&gt;
|where LIKE('Filename','filter')&lt;BR /&gt;
Now I need this where to search whether the filter value lies in the Filename. Again really thanks for your help!!!&lt;BR /&gt;
What I have tried and it didnt work&lt;BR /&gt;
|where LIKE('message.FileName','*filter&lt;/EM&gt;')&lt;BR /&gt;
|where LIKE('message.FileName','%filter%')&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:51:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500166#M32746</guid>
      <dc:creator>gurkiratsingh</dc:creator>
      <dc:date>2020-09-30T04:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500167#M32747</link>
      <description>&lt;P&gt;Try my answer.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 13:52:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500167#M32747</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-04-01T13:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500168#M32748</link>
      <description>&lt;P&gt;Use &lt;CODE&gt;match&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults
| eval fname="0000blahblah.blah"
| eval filter="0000"
| eval match=if(match(fname,filter),1,0)
| table fname filter match
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 01 Apr 2020 14:10:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500168#M32748</guid>
      <dc:creator>wmyersas</dc:creator>
      <dc:date>2020-04-01T14:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Change search query according to time in dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500169#M32749</link>
      <description>&lt;P&gt;Thanks guys now my query is resolved:-))&lt;BR /&gt;
Could you also help me a little more:&lt;BR /&gt;
(&lt;A href="https://answers.splunk.com/answers/814817/splunk-search-basic-queries.html"&gt;https://answers.splunk.com/answers/814817/splunk-search-basic-queries.html&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 10:49:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Change-search-query-according-to-time-in-dashboard/m-p/500169#M32749</guid>
      <dc:creator>gurkiratsingh</dc:creator>
      <dc:date>2020-04-02T10:49:36Z</dc:date>
    </item>
  </channel>
</rss>

