Dashboards & Visualizations

Dashboard studio-Scheduled export-Chained searches not taking earliest time query parameter from token

Sawn-CG
Engager

Some panels are not loading in the scheduled export mail with the error message "invalid earliest_time". These panels are all chained searches (extending from base search). 

A token is passed to the earliest_time query parameter to these panels, even though the other panels that use the same token load fine in the scheduled export. The other panels are not chained searches.

SawnCG_0-1763451132392.png


Also, all the panels load fine when the dashboard is run manually. Problem exists only in the scheduled export.

SawnCG_0-1763452356684.png

 

Are there any restrictions in dashboard studio schedule function that limits the number of searches?

 

Thanks in advance.

Labels (2)
0 Karma
1 Solution

forecastingLogs
Splunk Employee
Splunk Employee

I think you need to take into account he following Dashboard Studio Limitations listed here: https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/dashboard-studio/10.0/sha...

To be precise: 

  • Scheduled email exports use token default values to render content. If there is no default token value, the token will not set.

View solution in original post

forecastingLogs
Splunk Employee
Splunk Employee

I think you need to take into account he following Dashboard Studio Limitations listed here: https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/dashboard-studio/10.0/sha...

To be precise: 

  • Scheduled email exports use token default values to render content. If there is no default token value, the token will not set.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...