Dashboards & Visualizations

Time range ignored in dashboard and saved queries

Spidergawd
New Member
host="hostname*" SUSPENDING earliest ="-1d@d" latest = "-1d@d+24h"  | timechart count span=1m

In a dashboard or as a saved query the specified time range is ignored.
The query works if input manually.
Why ?

Tags (1)
0 Karma

lguinn2
Legend

I wonder if this is caused by the user timezone setting. Each user account can choose their own timezone. There is also a default timezone.

When input manually, the user's setting will apply. When run in a dashboard or as a saved query, it might be based on the setting for the owner of the knowledge object.

I am not sure this is the problem, but I think you should check this out.

0 Karma

Spidergawd
New Member

We are running version 5.0.3, build 163460 , "@d", thanks for that, I had tried -0d@d as well.
When I say the time range is ignored, the end of the time range is in the current day.
I need to distribute a clean comparable report of "yesterday"
thanks

0 Karma

lguinn2
Legend

"-1d@d+24h" is the same as"@d" FWIW

Which version of Splunk are you running?

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...