Dashboards & Visualizations

How to remove timezone from job.latestTime and job.earliestTime token?

BakaFon
Loves-to-Learn Everything

I need to add a line that show the number of results I get in the timeframe of the dashboard search using the job.earliestTime and job.latestTime tokens but if I use the replace function it doesn't work.

This is the code of the dashboard I used:

 

 

<html>
          <div class="custom-result-value">Results: $result$ in the time frame ($stime$ a $ltime$)</div>
        </html>
      <table id="test_table">
        <search>
          <query>| metadata type=sources | eval lastTime=strftime(lastTime, "%Y-%m-%d %H:%M:%S.%Q"), firstTime=strftime(firstTime, "%Y-%m-%d %H:%M:%S.%Q"), recentTime=strftime(recentTime, "%Y-%m-%d %H:%M:%S.%Q")</query>
          <earliest>-365d@d</earliest>
          <latest>now</latest>
          <sampleRatio>1</sampleRatio>
          <progress>
            <eval token="result">tonumber('job.resultCount')</eval>
            <eval token="ltime">tostring('job.latestTime')</eval>
            <eval token="stime">tostring('job.earliestTime')</eval>
            <eval token="stime">replace('$stime$',"\+\d+:00","")</eval>
            <eval token="stime">replace('$ltime$',"\+\d+:00","")</eval>
          </progress>
        </search>
        <option name="count">10</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">none</option>
        <option name="percentagesRow">false</option>
        <option name="rowNumbers">true</option>
        <option name="totalsRow">false</option>
        <option name="wrap">true</option>
      </table>

 

 

I get this regardless or not i use the replace command

BakaFon_0-1644327212342.png

The replace command works if used in a regular search

BakaFon_1-1644327699104.png

 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...