I have a dashboard for common search query, where i need to represent output of same search query in two time ranges. Time Range 1 and Time Range 2 added in input filters in dashboard. So now I am planning to create a base search for two different time ranges. After adding like below in the dashboard, data is not coming in panels output and when am clicking on open in search, output count is showing in query search. So please help me fix this issue. Below are the screenshots and base search's for reference.
Base Searches :
<search id="base_search_1">
<query>index=xxx source=xxx </query>
<earliest>$field1.earliest$</earliest>
<latest>$field1.latest$</latest>
</search>
========================
<search id="base_search_2">
<query>index=xxx source=xxx </query>
<earliest>$field2.earliest$</earliest>
<latest>$field2.latest$</latest>
</search>
Hi @asplunk789,
Adding a table command makes searches run on the search head. That is why it is slow.
Base searches should be more specific. Returning all raw data to panels is not the best practice. Please use stats or timechart command on your base search as a preparation for your panels.
Now the data coming after changed the base search query like below, but data loading in the panel is very very slow.
<query>index=xxx source=xxx | table * </query>