Dashboards & Visualizations

Set Custom TimeRange picker on Specific Splunk Studio Dashboard

viku7474
Explorer

I want to customize the Splunk studio dashboard in such a way that it shows last 7 days (each day) separately.  The requirement is only one dashboard. not globally. 

Today's date is 2nd May 2024. Now I want to showcase historical day here for last 7 days separately.
I want options like below in the presets so that if they select that day then users would see that day's data.
The historical dates should change dynamically.

1st May
31st April
30th April
29th April
28th April
27th April
26th April

viku7474_0-1714638343700.png

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Set your dropdown to this dynamic data source

| makeresults
| eval day=mvrange(0,7)
| mvexpand day
| eval day=relative_time(now(),"@d-".(1+day)."d")
| eval suffix=tonumber(trim(strftime(day, "%e")))
| eval suffix=case(suffix%10 == 1, "st", suffix%10 == 2, "nd", suffix%10 == 3, "rd", true(), "th")
| eval day=strftime(day,"%e").suffix." ".strftime(day,"%B")
| table day

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Set your dropdown to this dynamic data source

| makeresults
| eval day=mvrange(0,7)
| mvexpand day
| eval day=relative_time(now(),"@d-".(1+day)."d")
| eval suffix=tonumber(trim(strftime(day, "%e")))
| eval suffix=case(suffix%10 == 1, "st", suffix%10 == 2, "nd", suffix%10 == 3, "rd", true(), "th")
| eval day=strftime(day,"%e").suffix." ".strftime(day,"%B")
| table day

viku7474
Explorer

This is exactly what I was looking for.
but is it possible to incorporate along with the existing Time Range Picker?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If you mean to change the standard timepicker to include your special options into a modified timepicker, try adding new timeranges: Time ranges are configured in Settings -> Knowledge -> User interface -> Time ranges section of the Splunk interface.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...