Dashboards & Visualizations

Loadjob results for a week (Help please)

csatech245
Engager

I was able to build a large dashboard with 10+ panels using the loadjob command spanning the last day of any triggered results.  However, I am now looking to built the same dashboard where each panel will span a week (7-days) of any triggered results.

Loadjob was the only command that minimized loading of each panel.  Is there anyway to use loadjob, or a similar command, that shows a timechart spanning 7-days?

For example:

| loadjob savedsearch=tech123:Residential:"name of enabled alert" artifact_offset=0
| timechart span=1d count by incident_type

But I've tried using earliest=-7d in every  possible spot and I've used the time picker, but I haven't found a resolution yet... any thoughts or ideas or solutions?

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

loadjob is only loading the results of the saved search that has previously run.

If that is only doing 24 hours then you cannot get more information from that job.

Have you tried to increase the saved search time window?

 

0 Karma

csatech245
Engager

Ok, that was my thought, that it only showed the most recent previous triggered event.

How do I expand the search to a full previous week as you recommended?

0 Karma

bowesmana
SplunkTrust
SplunkTrust

You will have to edit the saved search and see what the time window is that it's using and change that. However, if you change the search it will change it for all people who are using that search. 

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...