Dashboards & Visualizations

Running Different Searches as per TIme Picker

sdhawanx
Path Finder

Hi All,

I have 2 different searches for a dashboard.

i want to run one search when the time range is Last seven days and the 2nd search when the time is any other value.

Any leads would be appreciated.

thanks in advance.

Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Set up one search with earliest -7d and latest now, and the other search to use a timepicker to provide a token with earliest and latest.

sdhawanx
Path Finder

I already have 2 searches, but only one time picker dropdown panel. I want to trigger search 1 when the time range is selected as Last 7 Days, and search 2 when other time range is selected. I am new to Splunk so i am having difficulty understanding how should I proceed. Should I trigger the searches using tokens or something like that ?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

How different are your two searches from each other?

0 Karma

sdhawanx
Path Finder

1st search is a saved search and the 2nd one is normal search.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could have two panels and use the depends attribute to hide/show each panel depending on the presence of a couple of tokens. You would set and unset these tokens in the timepicker depending on whether last 7 days is chosen or not.

0 Karma

sdhawanx
Path Finder

Yes I understand this, I am new to Splunk so can you help me with how to set these tokens

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...