Dashboards & Visualizations

How can we pass time from a search to time picker and all other panels?

Path Finder


We have 2 inputs
1 .Input has some base search and it gives some time value(consider peak time)
Ex: time value is as 03/21/2016 09:00:00

  1. 2nd Input is time picker, We need to pass peaktime on to time picker as earliest time and latest time should be 1min greater than earliest time.
    Ex: earliesttime = 03/21/2016 09:00:00 and latesttime = earliesttime + 1min(03/21/2016 09:01:00)

  2. All dashboard panels will take 2nd input as time value.

Can someone please help us with this customization?


Tags (1)
0 Karma


Something like this maybe?

  <label>Playing Around</label>
  <fieldset submitButton="true">
    <input type="dropdown" token="t_use_time" searchWhenChanged="true">
      <label>Found Time</label>
        <query>| tstats latest(_time) as last where index=_internal 
| eval use_time = relative_time(last,"-4h")
| eval show_time = strftime(use_time,"%D %H:%M:%S")</query>
        <eval token="form.t_time.earliest">$value$</eval>
        <eval token="form.t_time.latest">relative_time($value$,"+1m")</eval>
    <input type="time" token="t_time" searchWhenChanged="true" depends="my_earliest">
      <label>Choose Time:</label>
          <query>|  tstats count where index=_internal by sourcetype</query>
        <option name="drilldown">none</option>

The dropdown is simple search to get a "peak" time. When that dropdown changes, it sets the earliest/latest values of the timepicker accordingly - earliest is the value of the dropdown, latest is the value in the dropdown + 1 minute. Then the panel uses the timepicker's earliest/latest value.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...