Dashboards & Visualizations

Set latest time to clicked event time and earliest is relative to that time

lisheridan
Explorer

I have a SimpleResultsTable configured for drilldown which dispatches several child searches that display some charts. I want the child searches to set the latest time as the event time for what was clicked and I want the earliest time to be 1 day before that event time.

For example, if you click on an event that occurred at 11/5/2011 12:30:00 I want the child searches to show events from 11/4/2011 12:30:00 to 11/5/2011 12:30:00.

Is it possible to do this with earliest and latest and intentions?

0 Karma

lisheridan
Explorer

I think it is something like the following:

starttime=relative_time($time$, "-1d@s") endtime=$time$

... if $time$ is passed by row drilldown and can be picked up by ConvertToIntention.

I haven't been able to get variations of this to work yet though.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...