<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Converting time in Time token to limit results till a particular date in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331172#M159855</link>
    <description>&lt;P&gt;try below&lt;/P&gt;

&lt;P&gt;&amp;lt;form&amp;gt;&lt;BR /&gt;
  &amp;lt;label&amp;gt;test_tr&amp;lt;/label&amp;gt;&lt;BR /&gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;&lt;BR /&gt;
    &amp;lt;input type="time" token="time_token"&amp;gt;&lt;BR /&gt;
      &amp;lt;label&amp;gt;Select a time range before july 23rd&amp;lt;/label&amp;gt;&lt;BR /&gt;
      &amp;lt;default&amp;gt;&lt;BR /&gt;
        &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;&lt;BR /&gt;
        &amp;lt;latest&amp;gt;1500782400 &amp;lt;/latest&amp;gt;&lt;BR /&gt;
      &amp;lt;/default&amp;gt;&lt;BR /&gt;
    &amp;lt;/input&amp;gt;&lt;BR /&gt;
  &amp;lt;/fieldset&amp;gt;&lt;BR /&gt;
  &amp;lt;row&amp;gt;&lt;BR /&gt;
    &amp;lt;panel&amp;gt;&lt;BR /&gt;
      &amp;lt;table&amp;gt;&lt;BR /&gt;
        &amp;lt;search&amp;gt;&lt;BR /&gt;
          &amp;lt;query&amp;gt;index=_internal sourcetype=splunkd group=queue earliest=$time_token.earliest$ latest=1500782400  | stats count by group _time | reverse&amp;lt;/query&amp;gt;&lt;BR /&gt;&lt;BR /&gt;
        &amp;lt;/search&amp;gt;&lt;BR /&gt;
      &amp;lt;/table&amp;gt;&lt;BR /&gt;
    &amp;lt;/panel&amp;gt;&lt;BR /&gt;
  &amp;lt;/row&amp;gt;&lt;BR /&gt;
&amp;lt;/form&amp;gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 15:05:56 GMT</pubDate>
    <dc:creator>sbbadri</dc:creator>
    <dc:date>2020-09-29T15:05:56Z</dc:date>
    <item>
      <title>Converting time in Time token to limit results till a particular date</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331165#M159848</link>
      <description>&lt;P&gt;I need to create a panel in dashboard which gives me list of activities till 23rd July 2017. Now, I don't want the start time to be fixed but it to be user defined in the panel, so I have created a dropdown where users can select time duration. Now, endtime ensures the output never goes beyond 23rd July. But I want the start time to be dynamic based on what user select. So if user selects last 30 days, start time should be 25th June and results should be from 25th June to 23 July. When I run the below query, it gives a parse error. Any solution to this please. How can I set starttime based on what user selects in the dropdown.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  &amp;lt;title&amp;gt;Activities (till 23rd July 2017)&amp;lt;/title&amp;gt;
  &amp;lt;input type="time" token="time_token"&amp;gt;
    &amp;lt;label&amp;gt;Select Time duration&amp;lt;/label&amp;gt;
    &amp;lt;default&amp;gt;
      &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/default&amp;gt;
  &amp;lt;/input&amp;gt;

    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=ABC sourcetype=server123 starttime="$time_token.earliest$" endtime="07/23/2017:00:00:00" |stats count by activity
      &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;

&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 26 Jul 2017 21:44:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331165#M159848</guid>
      <dc:creator>pushpender07</dc:creator>
      <dc:date>2017-07-26T21:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Converting time in Time token to limit results till a particular date</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331166#M159849</link>
      <description>&lt;P&gt;Try below, i have converted July 23rd, 2017 to epoch time&lt;/P&gt;

&lt;P&gt;&amp;lt;query&amp;gt;index=ABC sourcetype=server123 earliest=$time_token.earliest$ latest=1500782400 |stats count by activity&amp;lt;/query&amp;gt;&lt;/P&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;P&gt;&amp;lt;query&amp;gt;index=ABC sourcetype=server123 starttime=$time_token.earliest$ endtime=1500782400 |stats count by activity&amp;lt;/query&amp;gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 04:18:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331166#M159849</guid>
      <dc:creator>sbbadri</dc:creator>
      <dc:date>2017-07-27T04:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Converting time in Time token to limit results till a particular date</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331167#M159850</link>
      <description>&lt;P&gt;@pushpender07, Using Time Control when the latest time is fixed and earliest keeps on changing can be confusing. For example "Last 7 Days" option in Time Control on 07/27 will set the earliest date to 07/20. When ideally "7 Days ago" option should be present to allow earliest time as 07/17 when the last date is fixed at 07/23. Using time control can be confusing/erroneous  when someone selects 07/26 or even Yesterday for earliest time then the Search will fail as fixed latest time 07/23 can not be earlier than earliest time.&lt;/P&gt;

&lt;P&gt;You can create your own dropdown to set valid earliest time.&lt;/P&gt;

&lt;P&gt;Please find run anywhere code for the two options&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3259i79FC1B8BCC275D0C/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  &amp;lt;search id="fromTimeControl"&amp;gt;
    &amp;lt;query&amp;gt;|makeresults&amp;lt;/query&amp;gt;
    &amp;lt;earliest&amp;gt;$selEarliestFromTimeControl.earliest$&amp;lt;/earliest&amp;gt;
    &amp;lt;done&amp;gt;
      &amp;lt;eval token="tokEarliestFromTimeControl"&amp;gt;strptime($job.earliestTime$,"%Y-%m-%d %H:%M:%S")&amp;lt;/eval&amp;gt;
    &amp;lt;/done&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;&amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;input type="time" token="selEarliestFromTimeControl" searchWhenChanged="true"&amp;gt;
        &amp;lt;label&amp;gt;Select Earliest (Time Control)&amp;lt;/label&amp;gt;
        &amp;lt;default&amp;gt;
          &amp;lt;earliest&amp;gt;-7d@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/default&amp;gt;
      &amp;lt;/input&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;input type="dropdown" token="selEarliestFromDropDown" searchWhenChanged="true"&amp;gt;
        &amp;lt;label&amp;gt;Select Earliest Time (Dropdown)&amp;lt;/label&amp;gt;
        &amp;lt;choice value="-30d"&amp;gt;30 days before&amp;lt;/choice&amp;gt;
        &amp;lt;choice value="-7d"&amp;gt;7 days before&amp;lt;/choice&amp;gt;
        &amp;lt;choice value="-1d"&amp;gt;1 day before&amp;lt;/choice&amp;gt;
        &amp;lt;change&amp;gt;
          &amp;lt;eval token="tokEarliestFromDropDown"&amp;gt;relative_time(strptime("07/23/2017:00:00:00","%m/%d/%Y:%H:%M:%S"),$value$)&amp;lt;/eval&amp;gt;
        &amp;lt;/change&amp;gt;
        &amp;lt;default&amp;gt;-7d&amp;lt;/default&amp;gt;
      &amp;lt;/input&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;title&amp;gt;Search from Time Control&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index="_internal" sourcetype="splunkd" log_level!="INFO" earliest="$tokEarliestFromTimeControl$" latest="07/23/2017:00:00:00"| timechart count&amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;title&amp;gt;Search from Time Dropdown&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index="_internal" sourcetype="splunkd" log_level!="INFO" earliest="$tokEarliestFromDropDown$" latest="07/23/2017:00:00:00"| timechart count&amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 27 Jul 2017 05:32:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331167#M159850</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-07-27T05:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Converting time in Time token to limit results till a particular date</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331168#M159851</link>
      <description>&lt;P&gt;Hi,  Thanks for the input. This does not solve the issue as I get a parse error when I try to use this.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 19:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331168#M159851</guid>
      <dc:creator>pushpender07</dc:creator>
      <dc:date>2017-07-27T19:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Converting time in Time token to limit results till a particular date</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331169#M159852</link>
      <description>&lt;P&gt;Hi, I will try to use it. As I am new to splunk, it might take time for me to figure this out. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 19:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331169#M159852</guid>
      <dc:creator>pushpender07</dc:creator>
      <dc:date>2017-07-27T19:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Converting time in Time token to limit results till a particular date</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331170#M159853</link>
      <description>&lt;P&gt;can you paste full error.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 19:20:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331170#M159853</guid>
      <dc:creator>sbbadri</dc:creator>
      <dc:date>2017-07-27T19:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Converting time in Time token to limit results till a particular date</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331171#M159854</link>
      <description>&lt;P&gt;I get the following error "Unable to parse -30d@d with format: %m/%d/%Y:%H:%M:%S". &lt;BR /&gt;
time_token.earliest is -30d@d by default&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 19:53:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331171#M159854</guid>
      <dc:creator>pushpender07</dc:creator>
      <dc:date>2017-07-27T19:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Converting time in Time token to limit results till a particular date</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331172#M159855</link>
      <description>&lt;P&gt;try below&lt;/P&gt;

&lt;P&gt;&amp;lt;form&amp;gt;&lt;BR /&gt;
  &amp;lt;label&amp;gt;test_tr&amp;lt;/label&amp;gt;&lt;BR /&gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;&lt;BR /&gt;
    &amp;lt;input type="time" token="time_token"&amp;gt;&lt;BR /&gt;
      &amp;lt;label&amp;gt;Select a time range before july 23rd&amp;lt;/label&amp;gt;&lt;BR /&gt;
      &amp;lt;default&amp;gt;&lt;BR /&gt;
        &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;&lt;BR /&gt;
        &amp;lt;latest&amp;gt;1500782400 &amp;lt;/latest&amp;gt;&lt;BR /&gt;
      &amp;lt;/default&amp;gt;&lt;BR /&gt;
    &amp;lt;/input&amp;gt;&lt;BR /&gt;
  &amp;lt;/fieldset&amp;gt;&lt;BR /&gt;
  &amp;lt;row&amp;gt;&lt;BR /&gt;
    &amp;lt;panel&amp;gt;&lt;BR /&gt;
      &amp;lt;table&amp;gt;&lt;BR /&gt;
        &amp;lt;search&amp;gt;&lt;BR /&gt;
          &amp;lt;query&amp;gt;index=_internal sourcetype=splunkd group=queue earliest=$time_token.earliest$ latest=1500782400  | stats count by group _time | reverse&amp;lt;/query&amp;gt;&lt;BR /&gt;&lt;BR /&gt;
        &amp;lt;/search&amp;gt;&lt;BR /&gt;
      &amp;lt;/table&amp;gt;&lt;BR /&gt;
    &amp;lt;/panel&amp;gt;&lt;BR /&gt;
  &amp;lt;/row&amp;gt;&lt;BR /&gt;
&amp;lt;/form&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:05:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331172#M159855</guid>
      <dc:creator>sbbadri</dc:creator>
      <dc:date>2020-09-29T15:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Converting time in Time token to limit results till a particular date</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331173#M159856</link>
      <description>&lt;P&gt;yup, this works. Thanks a bunch!&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 20:53:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Converting-time-in-Time-token-to-limit-results-till-a-particular/m-p/331173#M159856</guid>
      <dc:creator>pushpender07</dc:creator>
      <dc:date>2017-07-27T20:53:18Z</dc:date>
    </item>
  </channel>
</rss>

