<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help on base search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571955#M199307</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/102660"&gt;@jip31&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Oct 2021 07:24:33 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-10-22T07:24:33Z</dc:date>
    <item>
      <title>help on base search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571947#M199304</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;I try to use a base search between two single panel&lt;/P&gt;&lt;P&gt;the first single panel is on the last 24 h and the second panel must be on the last 7 days&lt;/P&gt;&lt;P&gt;but when i put&amp;nbsp; &amp;lt;earliest&amp;gt;-7d@h&amp;lt;/earliest&amp;gt;&amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt; in the second panel I have a validation warning!&lt;/P&gt;&lt;P&gt;what i have to do please?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search id="test"&amp;gt;
          &amp;lt;query&amp;gt;index=toto sourcetype=tutu  
| fields signaler 
| stats dc(signaler)&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search base="test"&amp;gt;
          &amp;lt;query&amp;gt;| stats dc(signaler)&amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 06:17:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571947#M199304</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2021-10-22T06:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: help on base search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571948#M199305</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/102660"&gt;@jip31&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;base searches must be outside panels and in each panel, you have to put the specific filter of the panel, in other words, something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;search id="test"&amp;gt;
    &amp;lt;query&amp;gt;
         index=toto sourcetype=tutu  
         | fields signaler 
         | stats dc(signaler)
    &amp;lt;/query&amp;gt;
    &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
    &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
&amp;lt;/search&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search base="test"&amp;gt;
          &amp;lt;query&amp;gt;
              ...
          &amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search base="test"&amp;gt;
          &amp;lt;query&amp;gt;
              ...
          &amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;But in your case you cannot use a base search because you have the same search but two different timeframes.&lt;/P&gt;&lt;P&gt;If you would use a base search you have to modify your search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;search id="test"&amp;gt;
    &amp;lt;query&amp;gt;
         index=toto sourcetype=tutu
         | eval type=if(_time-now()&amp;lt;86400,"Last24 hours","Last week")
         | fields signaler type
         | stats dc(signaler) BY type
    &amp;lt;/query&amp;gt;
    &amp;lt;earliest&amp;gt;-7d@d&amp;lt;/earliest&amp;gt;
    &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
&amp;lt;/search&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search base="test"&amp;gt;
          &amp;lt;query&amp;gt;
               | search type="Last24 hours"
          &amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search base="test"&amp;gt;
          &amp;lt;query&amp;gt;
               | search type="Last week"
          &amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;You can find more infos at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/Viz/Savedsearches#Post-process_searches_2" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/Viz/Savedsearches#Post-process_searches_2&lt;/A&gt;&amp;nbsp;or using the Splunk Dashboard Examples App (&lt;A href="https://splunkbase.splunk.com/app/1603/" target="_blank"&gt;https://splunkbase.splunk.com/app/1603/&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 06:40:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571948#M199305</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-10-22T06:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: help on base search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571950#M199306</link>
      <description>&lt;P&gt;perfect gcusello thanks&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 06:49:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571950#M199306</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2021-10-22T06:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: help on base search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571955#M199307</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/102660"&gt;@jip31&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 07:24:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571955#M199307</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-10-22T07:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: help on base search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571958#M199308</link>
      <description>&lt;P class="lia-align-left"&gt;just a little issue when I use&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;  | eval type=if(_time-now()&amp;lt;86400,"Last24 hours","Last week")&lt;/LI-CODE&gt;&lt;P&gt;I have an "unencoded &amp;lt; " message in my xml&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 07:46:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571958#M199308</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2021-10-22T07:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: help on base search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571982#M199316</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/102660"&gt;@jip31&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you put the search directly on dashboard XML source, you have to replace "&amp;lt;" with "&amp;amp;lt;".&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 10:45:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-base-search/m-p/571982#M199316</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-10-22T10:45:11Z</dc:date>
    </item>
  </channel>
</rss>

