<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Individual Time filter for each panel in dashboard in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389574#M42293</link>
    <description>&lt;P&gt;Hi , &lt;/P&gt;

&lt;P&gt;I have currently created a time filter by following this guide which applies to all my panels in the dashboard.&lt;BR /&gt;
 &lt;A href="https://www.splunk.com/blog/2016/09/16/i-cant-make-my-time-range-picker-pick.html"&gt;https://www.splunk.com/blog/2016/09/16/i-cant-make-my-time-range-picker-pick.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Now that I have a global time filter for all the dashboards, I was wondering if I could add in time filters for individual panels as well. &lt;/P&gt;

&lt;P&gt;Have tried to add the time input in the individual panel itself but I have the following error when I placed the token in the individual query. &lt;/P&gt;

&lt;P&gt;Would appreciate some advice. Thanks!&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6813i165F995DEE983AE3/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Apr 2019 10:03:58 GMT</pubDate>
    <dc:creator>synastraa</dc:creator>
    <dc:date>2019-04-03T10:03:58Z</dc:date>
    <item>
      <title>Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389574#M42293</link>
      <description>&lt;P&gt;Hi , &lt;/P&gt;

&lt;P&gt;I have currently created a time filter by following this guide which applies to all my panels in the dashboard.&lt;BR /&gt;
 &lt;A href="https://www.splunk.com/blog/2016/09/16/i-cant-make-my-time-range-picker-pick.html"&gt;https://www.splunk.com/blog/2016/09/16/i-cant-make-my-time-range-picker-pick.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Now that I have a global time filter for all the dashboards, I was wondering if I could add in time filters for individual panels as well. &lt;/P&gt;

&lt;P&gt;Have tried to add the time input in the individual panel itself but I have the following error when I placed the token in the individual query. &lt;/P&gt;

&lt;P&gt;Would appreciate some advice. Thanks!&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6813i165F995DEE983AE3/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 10:03:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389574#M42293</guid>
      <dc:creator>synastraa</dc:creator>
      <dc:date>2019-04-03T10:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389575#M42294</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;If you use base query you can't use the earliest and latest token there.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 10:41:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389575#M42294</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-04-03T10:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389576#M42295</link>
      <description>&lt;P&gt;Those properties must be before the closing &lt;CODE&gt;&amp;lt;/search&amp;gt;&lt;/CODE&gt; tag.&lt;/P&gt;

&lt;P&gt;Edit: oh, and what @vnravikumar says in his comment.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 10:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389576#M42295</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-04-03T10:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389577#M42296</link>
      <description>&lt;P&gt;@vnravikumar &lt;/P&gt;

&lt;P&gt;Yes I have a base query in my code. Is there still any approach I could take to do up individual time filters with a base query while keeping my global filter that filters everything together? Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 02:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389577#M42296</guid>
      <dc:creator>synastraa</dc:creator>
      <dc:date>2019-04-04T02:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389578#M42297</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;timepicker&amp;lt;/label&amp;gt;
  &amp;lt;search id="basequery"&amp;gt;
    &amp;lt;query&amp;gt;
      index=_internal |table _time,source,sourcetype
    &amp;lt;/query&amp;gt;
    &amp;lt;earliest&amp;gt;$time1.earliest$&amp;lt;/earliest&amp;gt;
    &amp;lt;latest&amp;gt;$time1.latest$&amp;lt;/latest&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;
    &amp;lt;input type="time" token="time1"&amp;gt;
      &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;@mon&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search base="basequery"&amp;gt;
          &amp;lt;query&amp;gt;|eventstats count by source|dedup source |table _time,source,count&amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;input type="time" token="time2"&amp;gt;
        &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
        &amp;lt;default&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/default&amp;gt;
      &amp;lt;/input&amp;gt;
      &amp;lt;input type="text"&amp;gt;
        &amp;lt;label&amp;gt;Earliest&amp;lt;/label&amp;gt;
        &amp;lt;default&amp;gt;$toEarliest$&amp;lt;/default&amp;gt;
      &amp;lt;/input&amp;gt;
      &amp;lt;input type="text"&amp;gt;
        &amp;lt;label&amp;gt;Latest&amp;lt;/label&amp;gt;
        &amp;lt;default&amp;gt;$toLatest$&amp;lt;/default&amp;gt;
      &amp;lt;/input&amp;gt;
      &amp;lt;input type="dropdown" depends="$hide$"&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| makeresults&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$time2.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$time2.latest$&amp;lt;/latest&amp;gt;
          &amp;lt;progress&amp;gt;
            &amp;lt;eval token="toEarliest"&amp;gt;strptime($job.earliestTime$,"%Y-%m-%dT%H:%M:%S.%3N%z")&amp;lt;/eval&amp;gt;
            &amp;lt;eval token="toLatest"&amp;gt;strptime($job.latestTime$,"%Y-%m-%dT%H:%M:%S.%3N%z")&amp;lt;/eval&amp;gt;
          &amp;lt;/progress&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/input&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search base="basequery"&amp;gt;
          &amp;lt;query&amp;gt;| eval earliest = $toEarliest$ | eval latest = if($toLatest$ &amp;amp;lt; 0,now(),$toLatest$)
          |  where _time &amp;amp;gt;=earliest AND _time &amp;amp;lt;=latest |eventstats count by source|dedup source |table _time,source,count&amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 04 Apr 2019 03:14:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389578#M42297</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-04-04T03:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389579#M42298</link>
      <description>&lt;P&gt;Hi vnravikumar,&lt;/P&gt;

&lt;P&gt;Could you provide some explanation as I'm kind of new to splunk and have some trouble understanding how this works. Greatly appreciated. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 03:57:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389579#M42298</guid>
      <dc:creator>synastraa</dc:creator>
      <dc:date>2019-04-04T03:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389580#M42299</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;As you know that we can't apply time pickers earliest and latest to the query that has used base query. For that, I had created dummy dropdown to get time2's earliest and latest token. Then I had used the same in the new panel.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 04:04:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389580#M42299</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-04-04T04:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389581#M42300</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;Have tried out the query and not sure if I am doing it right as it has return no results found. Thanks!&lt;BR /&gt;
 Have attached my query below. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;     &amp;lt;row&amp;gt;
     &amp;lt;panel&amp;gt;
       &amp;lt;input type="time" token="time1"&amp;gt;
         &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
         &amp;lt;default&amp;gt;
           &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
           &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
         &amp;lt;/default&amp;gt;
       &amp;lt;/input&amp;gt;
       &amp;lt;input type="dropdown" depends="$hide$"&amp;gt;
         &amp;lt;search&amp;gt;
               &amp;lt;query&amp;gt;|makeresults &amp;lt;/query&amp;gt;
           &amp;lt;earliest&amp;gt;$time1.earliest$&amp;lt;/earliest&amp;gt;
           &amp;lt;latest&amp;gt;$time1.latest$&amp;lt;/latest&amp;gt;
           &amp;lt;progress&amp;gt;
             &amp;lt;eval token="toEarliest"&amp;gt;strptime($job.earliestTime$,"%Y-%m-%d%H:%M:%S.%Q")&amp;lt;/eval&amp;gt;
             &amp;lt;eval token="toLatest"&amp;gt;strptime($job.latestTime$,"%Y-%m-%d%H:%M:%S.%Q")&amp;lt;/eval&amp;gt;
             &amp;lt;set token="jobEarliest"&amp;gt;$job.earliestTime$&amp;lt;/set&amp;gt;
             &amp;lt;set token="jobLatest"&amp;gt;$job.latestTime$&amp;lt;/set&amp;gt;
           &amp;lt;/progress&amp;gt;
         &amp;lt;/search&amp;gt;
       &amp;lt;/input&amp;gt;
     &amp;lt;/panel&amp;gt;
   &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;SLA Email Response Time Breached Rate %&amp;lt;/title&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search base="base_search"&amp;gt;
          &amp;lt;query&amp;gt;|eval earliest = $toEarliest$ |eval latest = if($toLatest$ &amp;amp;lt;0,now(),$toLatest$)
           |where _time &amp;amp;gt;=earliest AND _time &amp;amp;lt;=latest
           |where reportedsource="Email"|stats count(eval(responsetime &amp;amp;gt;2)) as "Breached" ,  count(eval(reportedsource ="Email"))  as total_count  | eval percentage= round((Breached/total_count)*100,2) |eval Breached Rate=percentage| table "Breached Rate"&amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="colorMode"&amp;gt;block&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeColors"&amp;gt;["0xf7bc38","0xf58f39","0xd93f3c"]&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeValues"&amp;gt;[50,80]&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;preview&amp;lt;/option&amp;gt;
        &amp;lt;option name="unit"&amp;gt;%&amp;lt;/option&amp;gt;
        &amp;lt;option name="unitPosition"&amp;gt;after&amp;lt;/option&amp;gt;
        &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 04 Apr 2019 04:45:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389581#M42300</guid>
      <dc:creator>synastraa</dc:creator>
      <dc:date>2019-04-04T04:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389582#M42301</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Do you have a record for that duration, can you please remove those condition and check.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 04:54:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389582#M42301</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-04-04T04:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389583#M42302</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;Yes I have records in that duration, have also tried all time but it still shows no results found. Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 05:00:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389583#M42302</guid>
      <dc:creator>synastraa</dc:creator>
      <dc:date>2019-04-04T05:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389584#M42303</link>
      <description>&lt;P&gt;Can you debug and check the values of two new tokens. like&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;      &amp;lt;input type="text"&amp;gt;
        &amp;lt;label&amp;gt;Earliest&amp;lt;/label&amp;gt;
        &amp;lt;default&amp;gt;$toEarliest$&amp;lt;/default&amp;gt;
      &amp;lt;/input&amp;gt;
      &amp;lt;input type="text"&amp;gt;
        &amp;lt;label&amp;gt;Latest&amp;lt;/label&amp;gt;
        &amp;lt;default&amp;gt;$toLatest$&amp;lt;/default&amp;gt;
      &amp;lt;/input&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 04 Apr 2019 05:45:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389584#M42303</guid>
      <dc:creator>vnravikumar</dc:creator>
      <dc:date>2019-04-04T05:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389585#M42304</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;I have attached a screenshot of what I am seeing.&lt;BR /&gt;
&lt;A href="https://imgur.com/a/JWC77Tc"&gt;https://imgur.com/a/JWC77Tc&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 06:53:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389585#M42304</guid>
      <dc:creator>synastraa</dc:creator>
      <dc:date>2019-04-04T06:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Individual Time filter for each panel in dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389586#M42305</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Still have not been able to get a solution for this. Is there anyone with a solution for this? Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 07:37:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Individual-Time-filter-for-each-panel-in-dashboard/m-p/389586#M42305</guid>
      <dc:creator>synastraa</dc:creator>
      <dc:date>2019-04-11T07:37:25Z</dc:date>
    </item>
  </channel>
</rss>

