<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk dashboard in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674826#M55256</link>
    <description>&lt;P&gt;You might have a bit differently prepared macros/searches you use there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jan 2024 11:16:35 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-01-19T11:16:35Z</dc:date>
    <item>
      <title>Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674792#M55244</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;General Filters&amp;lt;/title&amp;gt;
      &amp;lt;input type="time" token="time" id="my_date_range" searchWhenChanged="true"&amp;gt;
        &amp;lt;label&amp;gt;Select the Time Range&amp;lt;/label&amp;gt;
        &amp;lt;default&amp;gt;
          &amp;lt;earliest&amp;gt;-7d@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/default&amp;gt;
        &amp;lt;change&amp;gt;
          &amp;lt;eval token="time.earliest_epoch"&amp;gt;if('earliest'="",0,if(isnum(strptime('earliest', "%s")),'earliest',relative_time(now(),'earliest')))&amp;lt;/eval&amp;gt;
          &amp;lt;eval token="time.latest_epoch"&amp;gt;if(isnum(strptime('latest', "%s")),'latest',relative_time(now(),'latest'))&amp;lt;/eval&amp;gt;
          &amp;lt;eval token="macro_token"&amp;gt;if($time.latest_epoch$ - $time.earliest_epoch$ &amp;amp;gt; 2592000, "throughput_macro_summary_1d",if($time.latest_epoch$ - $time.earliest_epoch$ &amp;amp;gt; 86400, "throughput_macro_summary_1h","throughput_macro_raw"))&amp;lt;/eval&amp;gt;
          &amp;lt;eval token="form.span_token"&amp;gt;if($time.latest_epoch$ - $time.earliest_epoch$ &amp;amp;gt; 2592000, "d", if($time.latest_epoch$ - $time.earliest_epoch$ &amp;amp;gt; 86400, "h", $form.span_token$))&amp;lt;/eval&amp;gt;
      
        &amp;lt;/change&amp;gt;
      &amp;lt;/input&amp;gt;
      &amp;lt;/panel&amp;gt;&amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;title&amp;gt;Total Pallet&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;|`$macro_token$(span_token="$span_token$")` 
|strcat "raw" "," location group_name | timechart span=1d count by location&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$time.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$time.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.stackMode"&amp;gt;stacked&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 07:48:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674792#M55244</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-01-19T07:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674794#M55245</link>
      <description>&lt;P&gt;Hello Splunkers!!&lt;BR /&gt;I have pasted my dashboard code and in this text I am attaching screenshot of macro. When I am passing the below macros in dashboard it is not working fine. Please suggest how to proceed further ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1705650529395.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29023i8DC8D4FBAD5F09D4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1705650529395.png" alt="uagraw01_0-1705650529395.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 07:50:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674794#M55245</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-01-19T07:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674806#M55248</link>
      <description>&lt;P&gt;"not working fine" is not a useful phrase. Exactly, what is not working? What results are you getting? What results were you expecting?&lt;/P&gt;&lt;P&gt;(I created a similar dashboard and macro arrangement and it works fine for me!)&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 09:51:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674806#M55248</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-01-19T09:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674810#M55249</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two things what is "working" and "what is not working"&lt;/P&gt;&lt;P&gt;Working : Below data model is giving the results.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1705658077782.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29026i490338AEF59618EE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1705658077782.png" alt="uagraw01_0-1705658077782.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Not working :&amp;nbsp; When I use the data model under this macro`throughput_macro_raw(span=1d)` not giving any results.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_1-1705658204595.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29027i0A374B906280E9AD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_1-1705658204595.png" alt="uagraw01_1-1705658204595.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not working : As well in the dashboard below query is also not working&lt;/P&gt;&lt;PRE&gt;&amp;lt;query&amp;gt;|`$macro_token$(span_token="$span_token$")` 
|strcat "raw" "," location group_name | timechart span=1d count by location&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me to execute and fix these queries&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 09:58:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674810#M55249</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-01-19T09:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674812#M55250</link>
      <description>&lt;P&gt;In your first not working screenshot, you have used an argument called "span" but the macro definition calls the argument "span_token", hence the error.&lt;/P&gt;&lt;P&gt;For the second not working example, as I asked before, what exactly is not working? By the way, your dashboard source is incomplete so it could be something to do with the way you have set up span_token but you haven't shown this so I can't tell.&lt;/P&gt;&lt;P&gt;Please provide all relevant information to maximise your chances of getting a solution.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 10:06:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674812#M55250</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-01-19T10:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674813#M55251</link>
      <description>&lt;P&gt;As far as I can see, after you substitue your token you end up with (somewhere in the middle of your expanded macro)&lt;/P&gt;&lt;PRE&gt;| bin _time span=span=1d&lt;/PRE&gt;&lt;P&gt;Either remove the "span=" part from the macro definition or from the argument you're passing to it.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 10:07:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674813#M55251</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-19T10:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674816#M55252</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Even below is also not giving any results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And source I have already mentioned in datamodel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1705659449901.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29028i9C4A611621E95F82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1705659449901.png" alt="uagraw01_0-1705659449901.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 10:18:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674816#M55252</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-01-19T10:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674819#M55253</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;If, in this case, I remove the span= from all the below macros, then how do the span values pass through? And span_token values coming from the dashboard.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1705659970544.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29029i2CA4024D6B5833CF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1705659970544.png" alt="uagraw01_0-1705659970544.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;lt;change&amp;gt;&lt;BR /&gt;&amp;lt;eval token="time.earliest_epoch"&amp;gt;if('earliest'="",0,if(isnum(strptime('earliest', "%s")),'earliest',relative_time(now(),'earliest')))&amp;lt;/eval&amp;gt;&lt;BR /&gt;&amp;lt;eval token="time.latest_epoch"&amp;gt;if(isnum(strptime('latest', "%s")),'latest',relative_time(now(),'latest'))&amp;lt;/eval&amp;gt;&lt;BR /&gt;&amp;lt;eval token="macro_token"&amp;gt;if($time.latest_epoch$ - $time.earliest_epoch$ &amp;amp;gt; 2592000, "throughput_macro_summary_1d",if($time.latest_epoch$ - $time.earliest_epoch$ &amp;amp;gt; 86400, "throughput_macro_summary_1h","throughput_macro_raw"))&amp;lt;/eval&amp;gt;&lt;BR /&gt;&amp;lt;eval token="form.span_token"&amp;gt;if($time.latest_epoch$ - $time.earliest_epoch$ &amp;amp;gt; 2592000, "d", if($time.latest_epoch$ - $time.earliest_epoch$ &amp;amp;gt; 86400, "h", $form.span_token$))&amp;lt;/eval&amp;gt;&lt;BR /&gt;&amp;lt;/change&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 10:28:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674819#M55253</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-01-19T10:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674822#M55254</link>
      <description>&lt;P&gt;throughput_macro_raw() contains&lt;/P&gt;&lt;PRE&gt;| bin _time span=$span_token$&lt;/PRE&gt;&lt;P&gt;As you showed, you call it as&lt;/P&gt;&lt;PRE&gt;`throughput_macro_raw(span=1d)`&lt;/PRE&gt;&lt;P&gt;Since macro is a simple text expansion, your $span_token$ is getting substituted for "span=1d"&lt;/P&gt;&lt;P&gt;So your&lt;/P&gt;&lt;PRE&gt;span=$span_token$&lt;/PRE&gt;&lt;P&gt;is getting thus expanded to&lt;/P&gt;&lt;PRE&gt;span=span=1d&lt;/PRE&gt;&lt;P&gt;That's how macro expansion works.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 10:38:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674822#M55254</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-19T10:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674825#M55255</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;Nice explanation . But my approach is working fine on other dashboards.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 11:01:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674825#M55255</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-01-19T11:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674826#M55256</link>
      <description>&lt;P&gt;You might have a bit differently prepared macros/searches you use there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 11:16:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674826#M55256</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-19T11:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674827#M55257</link>
      <description>&lt;P&gt;The error message says it all - it looks like you can't use datamodel from within a macro. You could argue that this is a bug in the parser - please raise a support ticket with Splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 11:17:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674827#M55257</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-01-19T11:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674828#M55258</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Sure, I will. In the earlier chat, you said that you had used the same approach in your dashboard and it worked fine. Can you share with me that link for the reference?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 11:26:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674828#M55258</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-01-19T11:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674829#M55259</link>
      <description>&lt;P&gt;I didn't use datamodel, I was just testing using a token inside a macro&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 11:28:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674829#M55259</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-01-19T11:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674831#M55260</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;There is no need to raise a case; the macro is now working. I have removed the "|" from the macro used before the data model, and after that, it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1705664282748.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29030i2BB3EE46B56EEB29/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1705664282748.png" alt="uagraw01_0-1705664282748.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Let me check other stuffs, If needed I will post my queries here.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 11:39:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674831#M55260</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-01-19T11:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674832#M55261</link>
      <description>&lt;LI-CODE lang="markup"&gt;From here, "Total Pallet" panel is not giving any results. Can you please help me to identify error and suggestion to fix the error ? 
=======================================================================

&amp;lt;form version="1.1" theme="light"&amp;gt;
  &amp;lt;label&amp;gt;Throughput : Highbay&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;&amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;input type="time" token="time" id="my_date_range" searchWhenChanged="true"&amp;gt;
        &amp;lt;label&amp;gt;Select the Time Range&amp;lt;/label&amp;gt;
        &amp;lt;default&amp;gt;
          &amp;lt;earliest&amp;gt;-7d@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/default&amp;gt;
        &amp;lt;change&amp;gt;
          &amp;lt;eval token="time.earliest_epoch"&amp;gt;if('earliest'="",0,if(isnum(strptime('earliest', "%s")),'earliest',relative_time(now(),'earliest')))&amp;lt;/eval&amp;gt;
          &amp;lt;eval token="time.latest_epoch"&amp;gt;if(isnum(strptime('latest', "%s")),'latest',relative_time(now(),'latest'))&amp;lt;/eval&amp;gt;
          &amp;lt;eval token="macro_token"&amp;gt;if($time.latest_epoch$ - $time.earliest_epoch$ &amp;amp;gt; 2592000, "throughput_macro_summary_1d",if($time.latest_epoch$ - $time.earliest_epoch$ &amp;amp;gt; 86400, "throughput_macro_summary_1h","throughput_macro_raw"))&amp;lt;/eval&amp;gt;
          &amp;lt;eval token="form.span_token"&amp;gt;if($time.latest_epoch$ - $time.earliest_epoch$ &amp;amp;gt; 2592000, "d", if($time.latest_epoch$ - $time.earliest_epoch$ &amp;amp;gt; 86400, "h", $form.span_token$))&amp;lt;/eval&amp;gt;
        &amp;lt;/change&amp;gt;
      &amp;lt;/input&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;title&amp;gt;Total Pallet&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;|`$macro_token$(span_token="$span_token$")` 
|strcat "raw" "," location group_name | timechart span=1d count by location&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$time.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$time.latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.stackMode"&amp;gt;stacked&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 19 Jan 2024 11:45:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674832#M55261</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-01-19T11:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674833#M55262</link>
      <description>&lt;P&gt;Does it always fail i.e. with different time ranges selected or just some of them?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 12:30:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-dashboard/m-p/674833#M55262</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-01-19T12:30:33Z</dc:date>
    </item>
  </channel>
</rss>

