Dashboards & Visualizations

Set latest time to clicked event time and earliest is relative to that time

lisheridan
Explorer

I have a SimpleResultsTable configured for drilldown which dispatches several child searches that display some charts. I want the child searches to set the latest time as the event time for what was clicked and I want the earliest time to be 1 day before that event time.

For example, if you click on an event that occurred at 11/5/2011 12:30:00 I want the child searches to show events from 11/4/2011 12:30:00 to 11/5/2011 12:30:00.

Is it possible to do this with earliest and latest and intentions?

0 Karma

lisheridan
Explorer

I think it is something like the following:

starttime=relative_time($time$, "-1d@s") endtime=$time$

... if $time$ is passed by row drilldown and can be picked up by ConvertToIntention.

I haven't been able to get variations of this to work yet though.

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...