Dashboards & Visualizations

Filtering a table by a bucket_time span

sarak
Observer

Hi!

I have a dashboard with two parts - a table based on an existing dataset, and a column chart based on this query:

 

| bucket _time span=day | stats count by _time

 

The full table code looks like this:

 

{
    "type": "splunk.column",
    "dataSources": {
        "primary": "..."
    },
    "title": "...",
    "options": {
        "x": "> primary | seriesByName('_time')",
        "y": "> primary | frameBySeriesNames('count')",
        "legendDisplay": "off",
        "xAxisTitleVisibility": "hide",
        "yAxisTitleText": "...",
        "showYAxisWithZero": true
    },
    "eventHandlers": [],
    "context": {},
    "showProgressBar": false,
    "showLastUpdated": false
}

 

I want a click on any column to filter the table based on global_time - if I click on March 22, it filters the table to only show records where the _time is Mar 22 00:00:00 to Mar 22 23:59:59. How do I do that?

Labels (2)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...