Dashboards & Visualizations

Simple XML, custom timerange dropdown sample?

the_wolverine
Champion

Please provide sample Simple XML for custom timerange dropdown. I do not want to allow users to select whatever timerange they please, like "All Time" Or "Year to Date".

1 Solution

the_wolverine
Champion
   <searchTemplate>index=_internal earliest=$earliest$ | head 10000</searchTemplate>

    <fieldset autoRun="true" submitButton="false">
            <input type="dropdown" token="earliest" searchWhenChanged="true">
              <label>Select a time:</label>
              <choice value="-4h@h">Last 4 hours</choice>
              <choice value="-12h@h">Last 12 hours</choice>
              <choice value="-24h@h">Last 24 hours</choice>
              <default>-4h@h</default>
            </input>
          </fieldset>

View solution in original post

the_wolverine
Champion
   <searchTemplate>index=_internal earliest=$earliest$ | head 10000</searchTemplate>

    <fieldset autoRun="true" submitButton="false">
            <input type="dropdown" token="earliest" searchWhenChanged="true">
              <label>Select a time:</label>
              <choice value="-4h@h">Last 4 hours</choice>
              <choice value="-12h@h">Last 12 hours</choice>
              <choice value="-24h@h">Last 24 hours</choice>
              <default>-4h@h</default>
            </input>
          </fieldset>

anwarmian
Communicator

Great Job!!!!

0 Karma

ben_leung
Builder

Can this be done without modifying the CSS or HTML in the back end? I would also like to have custom time ranges for a dashboard but without using advance XML.

0 Karma

the_wolverine
Champion

yes 🙂 I will post an example in a moment unless someone beats me to it.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...