Dashboards & Visualizations

How to get date range in report from search?

KristianLind
Explorer

Hi, I have a search and a report for the search. 
How can I get the date range in the report? 

2022-05-17_13-32-51.jpg2022-05-17_13-35-02.jpg

0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| fieldformat info_min_time=strftime(info_min_time,"%F %T")

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| addinfo

This adds info fields to the event - info_min_time is the earliest, info_max_time is the latest from the search being executed.

0 Karma

KristianLind
Explorer

Thanks :slightly_smiling_face: 
Can I get that in human readable format? 

Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| fieldformat info_min_time=strftime(info_min_time,"%F %T")

KristianLind
Explorer

awesome :slightly_smiling_face: 
Can I remove some fields from addinfo  from the result. 
e.g I don't need

 2022-05-17_14-02-44.jpg

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| fields - info_*
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...