<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic timerange for the history command in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/timerange-for-the-history-command/m-p/106701#M6017</link>
    <description>&lt;P&gt;I've noticed that running the "| history" command will return different results based on the setting of the timerangepicker.  So my question is how can I define the earliest and latest values within the search bar, or in a dashboard panel's query?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| history earliest=-24h                 does not work
earliest=-24h | history                 does not work
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and I'm fairly confident that anything downstream from the history command won't be able to influence how many results were delivered initially by the history command.&lt;/P&gt;</description>
    <pubDate>Sat, 19 Oct 2013 01:32:51 GMT</pubDate>
    <dc:creator>paulathome</dc:creator>
    <dc:date>2013-10-19T01:32:51Z</dc:date>
    <item>
      <title>timerange for the history command</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/timerange-for-the-history-command/m-p/106701#M6017</link>
      <description>&lt;P&gt;I've noticed that running the "| history" command will return different results based on the setting of the timerangepicker.  So my question is how can I define the earliest and latest values within the search bar, or in a dashboard panel's query?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| history earliest=-24h                 does not work
earliest=-24h | history                 does not work
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and I'm fairly confident that anything downstream from the history command won't be able to influence how many results were delivered initially by the history command.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2013 01:32:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/timerange-for-the-history-command/m-p/106701#M6017</guid>
      <dc:creator>paulathome</dc:creator>
      <dc:date>2013-10-19T01:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: timerange for the history command</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/timerange-for-the-history-command/m-p/106702#M6018</link>
      <description>&lt;P&gt;I was using this in a dashboard panel to nicely display the last few searches that a user performed and I was able to set the earliest and latest in the Search module.  Couple that with a Pager, Table, HTML and a redirector module I was all set.&lt;/P&gt;

&lt;P&gt;Thanks Sideview Utils,&lt;BR /&gt;
  Paul&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2013 02:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/timerange-for-the-history-command/m-p/106702#M6018</guid>
      <dc:creator>paulathome</dc:creator>
      <dc:date>2013-10-19T02:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: timerange for the history command</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/timerange-for-the-history-command/m-p/106703#M6019</link>
      <description>&lt;P&gt;You would not be able to add earliest or latest value in a query (within search bar or a dashboard query) involving '|history'. The only option is the use timerangepicker (from searchbar) or from param "earliest" or latest within dashboard xml.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2013 06:31:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/timerange-for-the-history-command/m-p/106703#M6019</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2013-10-19T06:31:31Z</dc:date>
    </item>
  </channel>
</rss>

