Dashboards & Visualizations

Loadjob results for a week (Help please)

csatech245
Engager

I was able to build a large dashboard with 10+ panels using the loadjob command spanning the last day of any triggered results.  However, I am now looking to built the same dashboard where each panel will span a week (7-days) of any triggered results.

Loadjob was the only command that minimized loading of each panel.  Is there anyway to use loadjob, or a similar command, that shows a timechart spanning 7-days?

For example:

| loadjob savedsearch=tech123:Residential:"name of enabled alert" artifact_offset=0
| timechart span=1d count by incident_type

But I've tried using earliest=-7d in every  possible spot and I've used the time picker, but I haven't found a resolution yet... any thoughts or ideas or solutions?

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

loadjob is only loading the results of the saved search that has previously run.

If that is only doing 24 hours then you cannot get more information from that job.

Have you tried to increase the saved search time window?

 

0 Karma

csatech245
Engager

Ok, that was my thought, that it only showed the most recent previous triggered event.

How do I expand the search to a full previous week as you recommended?

0 Karma

bowesmana
SplunkTrust
SplunkTrust

You will have to edit the saved search and see what the time window is that it's using and change that. However, if you change the search it will change it for all people who are using that search. 

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...