Dashboards & Visualizations

Is it possible to create a Comparison Dashboard with dynamic time controls with my preexisting code?

blkhwk0833
Engager

Hello all,

New splunker here, so forgive me if this is totally way wrong to do it.
I was asked to make a comparison dashboard for application performance before the monthly patch and after. I was able to do so with the following code:  

 

 

 

index=erp sourcetype=erp_heartbeat tenant=AX2 earliest=-31d@month latest=-1d@month  
    | eval custate="Post-Update"
| append
    [ search index=erp sourcetype=erp_heartbeat tenant=AX2 earliest=-61d@month latest=-30d@month  
| eval custate="Pre-Update" ] 
| chart avg(duration)  by trans_name, custate

 

 

 

In a recent touchpoint, it was requested that users be able to change the dates to look at prior months' numbers. I can't figure out how to accomplish this as I'm using specific earliest and latest time modifiers   , so any help would be tremendously appreciated. 

Thank you all, as I've gotten this far with your community. 

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

here is how you can do it with simpleXML. I think that you can convert this easily to Dashboard Studio version if needed?

You just need to save that SPL to dashboard (Classic version) and then take it into edit. 

Select "Source" button on top left.

Add this after "label" element

  <fieldset submitButton="false">
    <input type="time" token="pre_update">
      <label>Pre Update</label>
      <default>
        <earliest>-61d@month</earliest>
        <latest>-30d@month</latest>
      </default>
    </input>
    <input type="time" token="post_update">
      <label></label>
      <default>
        <earliest>-31d@month</earliest>
        <latest>-1d@month</latest>
      </default>
    </input>
  </fieldset>

Then modify your query later on source like this

index=erp sourcetype=erp_heartbeat tenant=AX2 earliest=$post_update.earliest$ latest=$post_update.latest$   
    | eval custate="Post-Update"
| append
    [ search index=erp sourcetype=erp_heartbeat tenant=AX2 earliest=$pre_update.earliest$ latest=$pre_update.latest$  
| eval custate="Pre-Update" ] 
| chart avg(duration)  by trans_name, custate

Then save it and set needed permission to it.

Now the default times was those what are on upper box and users can change those with Time Selectors.

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here is how you can do it with simpleXML. I think that you can convert this easily to Dashboard Studio version if needed?

You just need to save that SPL to dashboard (Classic version) and then take it into edit. 

Select "Source" button on top left.

Add this after "label" element

  <fieldset submitButton="false">
    <input type="time" token="pre_update">
      <label>Pre Update</label>
      <default>
        <earliest>-61d@month</earliest>
        <latest>-30d@month</latest>
      </default>
    </input>
    <input type="time" token="post_update">
      <label></label>
      <default>
        <earliest>-31d@month</earliest>
        <latest>-1d@month</latest>
      </default>
    </input>
  </fieldset>

Then modify your query later on source like this

index=erp sourcetype=erp_heartbeat tenant=AX2 earliest=$post_update.earliest$ latest=$post_update.latest$   
    | eval custate="Post-Update"
| append
    [ search index=erp sourcetype=erp_heartbeat tenant=AX2 earliest=$pre_update.earliest$ latest=$pre_update.latest$  
| eval custate="Pre-Update" ] 
| chart avg(duration)  by trans_name, custate

Then save it and set needed permission to it.

Now the default times was those what are on upper box and users can change those with Time Selectors.

r. Ismo

0 Karma

blkhwk0833
Engager

Thank you @isoutamo!! This is exactly what I was trying to do. Now my dashboard is more dynamic.

blkhwk0833

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...