Dashboards & Visualizations

In a dashboard with a custom drilldown, how would I add 1ms to earliest=$click.value$ to get latest?

damucka
Builder

Hello,

In my dashboard, I need to define the custom drilldown where I would like to transport the _time, which is in the first column of my panel table. For that I need to have earliest and latest defined, where latest would be = earliest+1ms (at least that is how the Auto drilldown option gets it).

How would I do it?

My custom drilldown search looks as follows at the moment:

    index=mlbso sourcetype=*_transports source="*$sourcesid$*.$targetsid$" transport_exitcode=8 earliest=$click.value$ latest=???

Please adise.

Kind Regards,
Kamil

0 Karma
1 Solution

kmaron
Motivator

You should be able to do an eval to add the time.

 <drilldown>
           <eval token="latesttime">$click.value$+1ms</eval>
           <link>index=mlbso sourcetype=*_transports source="*$sourcesid$*.$targetsid$" transport_exitcode=8 earliest=$click.value$ latest=$latesttime$</link>
 </drilldown>

View solution in original post

0 Karma

kmaron
Motivator

You should be able to do an eval to add the time.

 <drilldown>
           <eval token="latesttime">$click.value$+1ms</eval>
           <link>index=mlbso sourcetype=*_transports source="*$sourcesid$*.$targetsid$" transport_exitcode=8 earliest=$click.value$ latest=$latesttime$</link>
 </drilldown>
0 Karma

damucka
Builder

Thank you.
It worked with

<eval token="latesttime">$click.value$+1ms</eval>
0 Karma

damucka
Builder

$click.value$+0.001

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...