Dashboards & Visualizations

How do I display _time on dashboard panel's title field?

pshangguan
New Member

Is there a simple way to display _time on the panel title fields? I am tying to create a dashboard and there are no date/time values in the index query, so I want to reply on _time.

Thanks,
Philip

Tags (1)
0 Karma
1 Solution

Vijeta
Influencer

You can have your query assuming you have a status field in event

<panel>
<title>$title$</title>
<search>
<query>
index=<yourindexname> | stats latest(status) as status, latest(_time) as time| fields status time
</query>
<done>
<set token="title">time<set>
</done>

View solution in original post

0 Karma

dstile
Explorer

This may get a little far from your original question, but including it in case it's helpful:

If you are providing a way for your user to select their search times anyway, then you can just use that token elsewhere in your title. Personally I would rather display the end of the search period rather than the last event found. If so, then use the earliest and latest modifiers, for example: $timer_tok.latest$

Alternately if you want to know when the Search Job stopped, try $job.latestTime$

This page has some great token info including both of those examples:
https://docs.splunk.com/Documentation/Splunk/7.2.0/Viz/tokens

0 Karma

Vijeta
Influencer

You can have your query assuming you have a status field in event

<panel>
<title>$title$</title>
<search>
<query>
index=<yourindexname> | stats latest(status) as status, latest(_time) as time| fields status time
</query>
<done>
<set token="title">time<set>
</done>
0 Karma

pshangguan
New Member

I have the following code:

<panel>
  <single>
    <title>$mytitle$</title>
    <search>
      <query>index=jenkins |spath job_name | search job_name="job/utl-dataflow-check-DEV2/" | stats latest(job_result) as status, latest(_time) as time | fields status time</query>
      <done>
        <set token="mytitle">time</set>
      </done>
      <earliest>-4h@m</earliest>
      <latest>now</latest>
    </search>
  </single>
</panel>

I am getting "time" displayed in the panel instead of the actual time. I run the query in splunk search and was able to see the status and the time.

0 Karma

Vijeta
Influencer

Please use below to set the time token. Also you may want to convert your time YYYY/mm/dd h:m:s format before passing it as token

 <set token="mytitle">$result.time$</set>
0 Karma

pshangguan
New Member

That worked. Thanks!!!

0 Karma

Vijeta
Influencer

Please accept the answer , if it resolved your issue 🙂

0 Karma

marycordova
SplunkTrust
SplunkTrust

latest(_time) as time

@marycordova
0 Karma

Vijeta
Influencer

Sorry was a typo, updated it. Thanks for pointing 🙂

0 Karma

marycordova
SplunkTrust
SplunkTrust

you should convert the comment to an answer 🙂

@marycordova
0 Karma

Vijeta
Influencer

The _time field will be there in your index. You want to display time field for all events or a single event? You can search on index and pass the _time field as token and pass the token to your panel title

0 Karma

pshangguan
New Member

A single event. I am trying to find the latest event and display its status(using single field panel), and I want to use the event time _time and display it in the title field.

0 Karma

msivill_splunk
Splunk Employee
Splunk Employee

Do you want the current time to appear on the dashboard or do you need a time from a query?

0 Karma

pshangguan
New Member

I want to catch the event time which I believe is in _time.

0 Karma
Get Updates on the Splunk Community!

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...