Dashboards & Visualizations

How to run searches using different time ranges in dropdown?

dzyfer
Path Finder

Hi, I would like to know how to run searches using different time ranges in dropdown.


For example, an input in the dropdown would be labelled "Yesterday", and I would like to assign 2 different time ranges to the same label, such that I can run 2 different searches using the separate time ranges by just selecting one input from the dropdown.

I have tried defining 4 tokens under the same label, but it doesn't work, ie.

 

<choice value="yesterday">Yesterday</choice>
 <condition label="Yesterday">
  <set token="custom_earliest">-8d@d+7h</set>
  <set token="custom_latest">@d+7h</set>
  <set token="breakdown_earliest">-1d@d+7h</set>
  <set token="breakdown_latest">@d+7h</set>
</condition>

 

 Thanks

Labels (4)
0 Karma
1 Solution

chaker
Contributor

A few things to try:

Print out the tokens in a panel to make sure they are being set to the value you expect. You may need to use dot notation, so what ever the token name of your input is.

<input type="dropdown" token="my_date">

my_date.custom_earliest
my_date.custom_latest

Try wrapping the time modifer in quotes

<set token="custom_latest">"@d+7h"</set>

Try matching condition value instead of label. Should be the same, but worth a try.

 

View solution in original post

0 Karma

chaker
Contributor

A few things to try:

Print out the tokens in a panel to make sure they are being set to the value you expect. You may need to use dot notation, so what ever the token name of your input is.

<input type="dropdown" token="my_date">

my_date.custom_earliest
my_date.custom_latest

Try wrapping the time modifer in quotes

<set token="custom_latest">"@d+7h"</set>

Try matching condition value instead of label. Should be the same, but worth a try.

 

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...