Hi at all,
I'm creating a dashboard to manage alerts.
I created a search that extract alerts information:
- timerange (-1d@d, -5m, etc...)
- search (index=XXX, sourcetype=XXX, conditions=XXX,.......)
I'd like to pass these parameters to another panel of my dashboard (or to another dashboard) to run the search that generated the alert in the same time range and obtain the results that generated alert.
However, I'm have problems building "earliest" and "latest" parameters in my first search for the second one. Could you help me?
Thank You in advance.
The first search (Alert Search) is already OK, the problem is to correctly calculate StartTime and EndTime to pass to the second one:
I reached to calculate StartTime and EndTime in my first panel.
...| eval EndTime=strftime(time,"%m/%d/%Y:%H:%M:%S") | eval StartTime=strftime(relativetime(_time,timerange),"%m/%d/%Y:%H:%M:%S")
where timerange is a field with timerange values (-1d, -2m@m, etc...)
The problem now is hot to pass these parametrs to the second panel:
if I put these parametrs in the second panel query (at the beginning of the query), it takes them, but it isn't OK for my need because in the search there are some subsearches that don't take time modifiers.
Is it possible to pass parametrs to the earliest and latest row of the dashboard?
Thank you in advance.
I inserted in the drilldown URL the time tokens:
<drilldown> <link>details_by_protocol?cs_uri_scheme=$click.name2$&TimeFrom=$Time.earliest$&TimeTo=$Time.latest$</link> </drilldown>