Dashboards & Visualizations

Is there a function to turn a time range into human-readable string?

unitedmarsupial
Path Finder

I've created a dashboard with a shared "time-input" (named range) -- all of the panels refer to it:

      <earliest>$range.earliest$</earliest>
      <latest>$range.latest$</latest>

I'd like each panel's title to reflect the currently-picked range -- showing it in human-readable form like "Last 4 hours" or "Yesterday from 2am to 3am". Is this possible?

Update: Ok, I found I can add something like this to the titles:

... between $range.earliest$ and $range.latest$

and it will be translated to, for example between -7d@h and now. Maybe, there are better alternatives?..

0 Karma

vnravikumar
Champion

Hi

Check this

<input type="time" searchWhenChanged="true">
        <label>Enter the time range</label>
        <default>
          <earliest>-1d@d</earliest>
          <latest>@d</latest>
        </default>
        <change>
          <set token="displayTime">($label$)</set>
        </change>
      </input>

to4kawa
Ultra Champion

It is enough to use in the Last something.
If Today is specified, it is regrettable that it will be Custom time.

0 Karma

to4kawa
Ultra Champion
| makeresults 
| addinfo 
| eval _time=info_max_time 
| reltime 
| rename reltime as last_time 
| eval _time=info_min_time 
| reltime 
| rename reltime as first_time
| eval output_text="Search period: between ".first_time." to ".last_time

you can hide the panel and pass output_text in tokens.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check out the reltime function.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...