Dashboards & Visualizations

How to count all created_date and closed_date that lies within specified time picker range?

Nic
Engager

Hi all,

I'm new to Dashboard Studio and I'm running into an issue. I have two dates in my dataset: a created_date and a closed_date. I want to count all created_date that lies in the specified time picker range, and I want to do the same for closed_date.

Splunk automatically creates tokens, $global_time.earliest$ and $global_time.latest$. I tried to compare using these tokens, but this doesn't work:

| eval earliest = $global_time.earliest$
| eval latest = $global_time.latest$
| eval epochcreated_date =strptime(created_date, "%Y-%m-%dT%H:%M:%S.%3N%z")
| where epochcreated_date>= earliest AND epochcreated_date<= latest

I hope someone here can point me in the right direction. Thanks in advance.

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

You could try using the times that the search is actually using - these are provided by the addinfo command

| addinfo
| eval epochcreated_date =strptime(created_date, "%Y-%m-%dT%H:%M:%S.%3N%z")
| where epochcreated_date>= info_min_time AND epochcreated_date<= info_max_time

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could try using the times that the search is actually using - these are provided by the addinfo command

| addinfo
| eval epochcreated_date =strptime(created_date, "%Y-%m-%dT%H:%M:%S.%3N%z")
| where epochcreated_date>= info_min_time AND epochcreated_date<= info_max_time
0 Karma

Nic
Engager

Thank you so much!!! This is exactly what I needed, awesome!

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...