Dashboards & Visualizations

How to use 10 different time ranges in Dashboard Studio

alexis
Explorer

Hi everyone,

There are 10 single value graphs on my Dashboard. I don't want to use global time Range. How can I add for each?

Labels (2)
0 Karma
1 Solution

Stefanie
Builder

In Dashboard Studio, you can specify this by directly modifying the Source. 

Once you create your graphs, in the source you can add a stanza for queryParameters and then specify the earliest and latest for your your search.

The earliest and latest are Time Modifiers as specified in https://docs.splunk.com/Documentation/SCS/current/Search/Timemodifiers

and also https://docs.splunk.com/Documentation/SCS/current/Search/Specifyrelativetime 

 

Here's an example. This is a line graph that pulls the count by index for the past two hours up until now.

 
"visualizations": {
		"viz_chart_1": {
			"type": "viz.line",
			"options": {
				"drilldown": "none",
				"refresh.display": "progressbar"
			},
			"dataSources": {
				"primary": "ds_search_1"
			}
		},
"dataSources": {
		"ds_search_1": {
			"type": "ds.search",
			"options": {
				"query": "|tstats count by index",
				"queryParameters": {
					"earliest": "-2h@h",
					"latest": "now"
				}
			}
		},

 

View solution in original post

alexis
Explorer

Thanks a lot . Stefanie

Stefanie
Builder

In Dashboard Studio, you can specify this by directly modifying the Source. 

Once you create your graphs, in the source you can add a stanza for queryParameters and then specify the earliest and latest for your your search.

The earliest and latest are Time Modifiers as specified in https://docs.splunk.com/Documentation/SCS/current/Search/Timemodifiers

and also https://docs.splunk.com/Documentation/SCS/current/Search/Specifyrelativetime 

 

Here's an example. This is a line graph that pulls the count by index for the past two hours up until now.

 
"visualizations": {
		"viz_chart_1": {
			"type": "viz.line",
			"options": {
				"drilldown": "none",
				"refresh.display": "progressbar"
			},
			"dataSources": {
				"primary": "ds_search_1"
			}
		},
"dataSources": {
		"ds_search_1": {
			"type": "ds.search",
			"options": {
				"query": "|tstats count by index",
				"queryParameters": {
					"earliest": "-2h@h",
					"latest": "now"
				}
			}
		},

 

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...