Alerting

Dashboard time not showing

majilan1
Path Finder

Hi,

I want to display time on my dashboard but all I see just two fields with data any help with the search to populate the rest of the fields would be appreciated.

I have attached my dashboard.

my search that looks like this:

Index=a sourcetype=b earliest=-1d

[| inputlookup M003_siem_ass_list where FMA_id=*OS -001* | stats  values(ass) as search

| eval seaqqrch=mvjoin(search,", OR ")]

| fields ip  FMA_id   _time  d_role

| stats latest(_time) as _time values(*) by ip

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Time only displays well when it is used as the x-axis on charts.

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...