Dashboards & Visualizations

How to remove timezone from job.latestTime and job.earliestTime token?

BakaFon
Loves-to-Learn Everything

I need to add a line that show the number of results I get in the timeframe of the dashboard search using the job.earliestTime and job.latestTime tokens but if I use the replace function it doesn't work.

This is the code of the dashboard I used:

 

 

<html>
          <div class="custom-result-value">Results: $result$ in the time frame ($stime$ a $ltime$)</div>
        </html>
      <table id="test_table">
        <search>
          <query>| metadata type=sources | eval lastTime=strftime(lastTime, "%Y-%m-%d %H:%M:%S.%Q"), firstTime=strftime(firstTime, "%Y-%m-%d %H:%M:%S.%Q"), recentTime=strftime(recentTime, "%Y-%m-%d %H:%M:%S.%Q")</query>
          <earliest>-365d@d</earliest>
          <latest>now</latest>
          <sampleRatio>1</sampleRatio>
          <progress>
            <eval token="result">tonumber('job.resultCount')</eval>
            <eval token="ltime">tostring('job.latestTime')</eval>
            <eval token="stime">tostring('job.earliestTime')</eval>
            <eval token="stime">replace('$stime$',"\+\d+:00","")</eval>
            <eval token="stime">replace('$ltime$',"\+\d+:00","")</eval>
          </progress>
        </search>
        <option name="count">10</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">none</option>
        <option name="percentagesRow">false</option>
        <option name="rowNumbers">true</option>
        <option name="totalsRow">false</option>
        <option name="wrap">true</option>
      </table>

 

 

I get this regardless or not i use the replace command

BakaFon_0-1644327212342.png

The replace command works if used in a regular search

BakaFon_1-1644327699104.png

 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...