Dashboards & Visualizations

Why are the two base searches throw warnings in a dashboard?

macadminrohit
Contributor

I have two base searches in a dashboard, not sure if that is at all possible. But as soon as i use the second base search created, i get warnings with this :

$timer.earliest$
$timer.latest$

Warning is : Unknown node is not allowed here. Before creating the second base search this warning was not existing.

macadminrohit
Contributor

I think i found the mistake, I should be using the timer tokens only in the base search whereas i was using in all the sub searches 🙂

cmerriman
Super Champion

You're exactly right, @macadminrohit . Base searches only require earliest and latest in the base search itself and do not expect them to be called out in any of the searches referencing them. I will move your comment to an answer if you'd like to accept it and close out the question.

azdale
Engager

Hello,
I think the time picker should also be included in your base search. So that its something like this. What do you currently have?

"base search query"

$TimeRangePkr.earliest$

$TimeRangePkr.latest$

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...

Index This | How many sevens are there between 1 and 100?

August 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...