Dashboards & Visualizations

Loadjob results for a week (Help please)

csatech245
Engager

I was able to build a large dashboard with 10+ panels using the loadjob command spanning the last day of any triggered results.  However, I am now looking to built the same dashboard where each panel will span a week (7-days) of any triggered results.

Loadjob was the only command that minimized loading of each panel.  Is there anyway to use loadjob, or a similar command, that shows a timechart spanning 7-days?

For example:

| loadjob savedsearch=tech123:Residential:"name of enabled alert" artifact_offset=0
| timechart span=1d count by incident_type

But I've tried using earliest=-7d in every  possible spot and I've used the time picker, but I haven't found a resolution yet... any thoughts or ideas or solutions?

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

loadjob is only loading the results of the saved search that has previously run.

If that is only doing 24 hours then you cannot get more information from that job.

Have you tried to increase the saved search time window?

 

0 Karma

csatech245
Engager

Ok, that was my thought, that it only showed the most recent previous triggered event.

How do I expand the search to a full previous week as you recommended?

0 Karma

bowesmana
SplunkTrust
SplunkTrust

You will have to edit the saved search and see what the time window is that it's using and change that. However, if you change the search it will change it for all people who are using that search. 

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!