Dashboards & Visualizations

How to add custom time range in Splunk dashboard?

RanjiRaje
Explorer

Hi All,

I am in need of your help. I am building a dashboard and included time range picker as input.

I have hidden some of the options in time range picker (relative panel, date range panel, realtime panel etc)

I am trying to add new time option under presets (last 15 days). Please guide me how to achieve this

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @RanjiRaje,

to create time presets you have to go in [Settings > User Interface > Time Ranges > new Time Range] and add the speifications of your new time range:

  • name. name of the new time range, unique but not relevant,
  • label: label displayed in the Tme Picker,
  • Order: position in the Presets list,
  • earliest: earliest time,
  • latest. latest time.

Remeber to assign the correct grants to the new time range, to be displayed by the correct roles of users.

For more infos see at https://docs.splunk.com/Documentation/Splunk/9.0.4/Search/Selecttimerangestoapply#Customize_the_list...

Ciao.

Giuseppe

0 Karma

RanjiRaje
Explorer

Hi Sir, thanks for your reply. I tried with the above steps and can see the newly added time range in splunk web which is not required.

I need this "Last 15 days" time range (under time range picker input) under presets only in my dashboard.

Is there any XML that i can use to achieve this. Please suggest

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @RanjiRaje,

this is the only way to create time presets.

If you want that his preset is visible only for your role, you have to add specific grants to this role.

Ciao.

Giuseppe

0 Karma

RanjiRaje
Explorer

Hi sir, thanks for your guidance. I made it as dropdown input and provided the list of time range inputs that Im requiring in my dashboard

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...