<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk dashboard in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549776#M37925</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Yeah in yesterday's time range result is there . But don't know why I am getting no results.I have used the same query as you mentioned.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Apr 2021 08:14:00 GMT</pubDate>
    <dc:creator>Als123</dc:creator>
    <dc:date>2021-04-29T08:14:00Z</dc:date>
    <item>
      <title>Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549627#M37905</link>
      <description>&lt;P&gt;My requirement is like I need to create two panels in my dashboard.&lt;/P&gt;&lt;P&gt;First Panel: When I am choosing last 15 min means I need to get the values from 10 am to 10.15am for today's date(for example).&lt;/P&gt;&lt;P&gt;Second Panel: In second Panel I need to get the data from 10am to 10.15 am for yesterday's date.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It should be like comparison between today's data vs yesterday's data.please help me how to frame query for second Panel?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 14:03:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549627#M37905</guid>
      <dc:creator>Als123</dc:creator>
      <dc:date>2021-04-28T14:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549632#M37906</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233936"&gt;@Als123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to put in your dashboard the Time Picker setted e.g to the last 15 minutes.&lt;/P&gt;&lt;P&gt;In the first panel, you take the value from the Time Picker as it is.&lt;/P&gt;&lt;P&gt;In the second panel you use a search like this (if the Time Picket token is called e.g. "Time"):&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;your_search [ | makeresults | eval earliest=relative_time($Time.earliest$,"-1d"), latest=relative_time($Time.latest$,"-1d") | fields earliest latest ]
| ...&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 14:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549632#M37906</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-28T14:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549637#M37907</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I am getting Error in 'eval' command:The expression is malformed.Expected ).&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 14:34:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549637#M37907</guid>
      <dc:creator>Als123</dc:creator>
      <dc:date>2021-04-28T14:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549638#M37908</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233936"&gt;@Als123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the search seems to be correct!&lt;/P&gt;&lt;P&gt;could you share your search?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 14:38:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549638#M37908</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-28T14:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549640#M37909</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I gave my query like this .&lt;/P&gt;&lt;P&gt;&amp;lt;query&amp;gt;index=xyz |makeresults|eval earliest=relative_time($field1.earliest$,"-1d"),latest=relative_time($field1.latest$,"-1d")|fields earliest latest|timechart span =5m count by specification &amp;lt;/query&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My token name is field1&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 14:41:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549640#M37909</guid>
      <dc:creator>Als123</dc:creator>
      <dc:date>2021-04-28T14:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549644#M37910</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233936"&gt;@Als123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it isn't correct: the square parenthesys of the subsearch are missing&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;query&amp;gt;
     index=xyz [ | makeresults | eval earliest=relative_time($field1.earliest$,"-1d"), latest=relative_time($field1.latest$,"-1d") | fields earliest latest ]
     | timechart span =5m count by specification 
&amp;lt;/query&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;In few words, you use a subsearch to calculate the new variables earliest and latest.&lt;/P&gt;&lt;P&gt;One hint: give always a name to the tokens, don't leave $field1$.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 14:46:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549644#M37910</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-28T14:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549646#M37911</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I have used the query u mentioned. But again I am getting "Erroe in 'eval' command.The expression is malformed.Expected)" error in my panel.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 14:53:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549646#M37911</guid>
      <dc:creator>Als123</dc:creator>
      <dc:date>2021-04-28T14:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549729#M37919</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;If I am modifying the query like this ("$field1.earliest$"), I am not getting eval error but I am not getting any search results.&lt;/P&gt;&lt;P&gt;&amp;lt;query&amp;gt; index=xyz [ | makeresults | eval earliest=relative_time("$field1.earliest$","-1d"), latest=relative_time("$field1.latest$","-1d") | fields earliest latest ] | timechart span =5m count by specification &amp;lt;/query&lt;/P&gt;&lt;P&gt;Please help on this.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 02:21:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549729#M37919</guid>
      <dc:creator>Als123</dc:creator>
      <dc:date>2021-04-29T02:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549748#M37920</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233936"&gt;@Als123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=xyz [ search index=_internal ! head 1 | addinfo | eval earliest=info_min_time-86400, latest=info_max_time-86400 | fields earliest latest ] 
| timechart span =5m count by specification&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 06:18:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549748#M37920</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-29T06:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549762#M37921</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I am getting No results found for above query.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 07:40:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549762#M37921</guid>
      <dc:creator>Als123</dc:creator>
      <dc:date>2021-04-29T07:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549767#M37922</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233936"&gt;@Als123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry:a typing error, please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=xyz [ search index=_internal | head 1 | addinfo | eval earliest=info_min_time-86400, latest=info_max_time-86400 | fields earliest latest ] 
| timechart span=5m count by specification&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 07:54:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549767#M37922</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-29T07:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549772#M37923</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I have tried like this before also .In this case also I got No results found only.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 08:10:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549772#M37923</guid>
      <dc:creator>Als123</dc:creator>
      <dc:date>2021-04-29T08:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549774#M37924</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233936"&gt;@Als123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;are you sure to have events in the yesterday time range?&lt;/P&gt;&lt;P&gt;I tried this search on _internal in my Splunk and it runs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 08:12:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549774#M37924</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-29T08:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549776#M37925</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Yeah in yesterday's time range result is there . But don't know why I am getting no results.I have used the same query as you mentioned.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 08:14:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549776#M37925</guid>
      <dc:creator>Als123</dc:creator>
      <dc:date>2021-04-29T08:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549779#M37926</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now it is working fine for me.Thank you so much for your help.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 08:25:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549779#M37926</guid>
      <dc:creator>Als123</dc:creator>
      <dc:date>2021-04-29T08:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549780#M37927</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233936"&gt;@Als123&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first check the search using _internal, so you'r sure that the search is correct.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal [ search index=_internal | head 1 | addinfo | eval earliest=info_min_time-86400, latest=info_max_time-86400 | fields earliest latest ] 
| timechart span=5m count&lt;/LI-CODE&gt;&lt;P&gt;Then separately run each search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal | head 1 | addinfo | eval earliest=info_min_time-86400, latest=info_max_time-86400 | fields earliest latest &lt;/LI-CODE&gt;&lt;P&gt;and then using the yesterday time frame&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=xyz 
| timechart span=5m count by specification&lt;/LI-CODE&gt;&lt;P&gt;Then if you have results in both the searches, try:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=xyz [ search index=_internal | head 1 | addinfo | eval earliest=info_min_time-86400, latest=info_max_time-86400 | fields earliest latest ] &lt;/LI-CODE&gt;&lt;P&gt;So you can see where's the problem .&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: tell me if I can help you more, otherwise, Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 08:25:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549780#M37927</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-29T08:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549818#M37928</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for your help. I am having another one question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In panel 1, I am having two graphs (Success and Failure) for present date.&lt;/P&gt;&lt;P&gt;In panel 2, I am having two graphs (Success and Failure) for yesterday's date.&lt;/P&gt;&lt;P&gt;I need all 4 graphs (panel 1 and panel 2) in a single graph. With yesterday and today named in X or Y axis. Please help on this .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 11:10:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/549818#M37928</guid>
      <dc:creator>Als123</dc:creator>
      <dc:date>2021-04-29T11:10:18Z</dc:date>
    </item>
  </channel>
</rss>

