Dashboards & Visualizations

How to run searches using different time ranges in dropdown?

dzyfer
Path Finder

Hi, I would like to know how to run searches using different time ranges in dropdown.


For example, an input in the dropdown would be labelled "Yesterday", and I would like to assign 2 different time ranges to the same label, such that I can run 2 different searches using the separate time ranges by just selecting one input from the dropdown.

I have tried defining 4 tokens under the same label, but it doesn't work, ie.

 

<choice value="yesterday">Yesterday</choice>
 <condition label="Yesterday">
  <set token="custom_earliest">-8d@d+7h</set>
  <set token="custom_latest">@d+7h</set>
  <set token="breakdown_earliest">-1d@d+7h</set>
  <set token="breakdown_latest">@d+7h</set>
</condition>

 

 Thanks

Labels (4)
0 Karma
1 Solution

chaker
Contributor

A few things to try:

Print out the tokens in a panel to make sure they are being set to the value you expect. You may need to use dot notation, so what ever the token name of your input is.

<input type="dropdown" token="my_date">

my_date.custom_earliest
my_date.custom_latest

Try wrapping the time modifer in quotes

<set token="custom_latest">"@d+7h"</set>

Try matching condition value instead of label. Should be the same, but worth a try.

 

View solution in original post

0 Karma

chaker
Contributor

A few things to try:

Print out the tokens in a panel to make sure they are being set to the value you expect. You may need to use dot notation, so what ever the token name of your input is.

<input type="dropdown" token="my_date">

my_date.custom_earliest
my_date.custom_latest

Try wrapping the time modifer in quotes

<set token="custom_latest">"@d+7h"</set>

Try matching condition value instead of label. Should be the same, but worth a try.

 

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...