Dashboards & Visualizations

How can I make the time range picker in a dropdown take two times?

msachdeva3
Explorer

I want to use time range in a way that it takes 2 times. It takes from start of the day always + then the user selects the time range.

08/10/2017
00:00:00
and
08/11/2017
24:00:00

How can I accommodate this in my query or can fix the time picker in drop down?

Thanks

1 Solution

woodcock
Esteemed Legend

Create a text field and call it DaysAgo and have users type in a number of days back to go and create another token based on that and use this to run your search from inside the query with earliest= and latest= like this shows:

| makeresults 
| eval DaysAgo = 3 
| eval DaysAgoMinusOne = DaysAgo - 1 
| map search="search index=main earliest=-$DaysAgo$d@d latest =-$DaysAgoMinusOne$d@d | addinfo | head 1 | table info_m* | convert ctime(*time)"

In this example, a user entering 3 in your text field is represented by my | eval DaysAgo = 3 and your form's search will be very much like my map's search string, using the same tokens in the same way but doing different stuff after the first pipe (mine just shows that it really does work).

View solution in original post

0 Karma

woodcock
Esteemed Legend

Create a text field and call it DaysAgo and have users type in a number of days back to go and create another token based on that and use this to run your search from inside the query with earliest= and latest= like this shows:

| makeresults 
| eval DaysAgo = 3 
| eval DaysAgoMinusOne = DaysAgo - 1 
| map search="search index=main earliest=-$DaysAgo$d@d latest =-$DaysAgoMinusOne$d@d | addinfo | head 1 | table info_m* | convert ctime(*time)"

In this example, a user entering 3 in your text field is represented by my | eval DaysAgo = 3 and your form's search will be very much like my map's search string, using the same tokens in the same way but doing different stuff after the first pipe (mine just shows that it really does work).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...