Dashboards & Visualizations

Why are the two base searches throw warnings in a dashboard?

macadminrohit
Contributor

I have two base searches in a dashboard, not sure if that is at all possible. But as soon as i use the second base search created, i get warnings with this :

$timer.earliest$
$timer.latest$

Warning is : Unknown node is not allowed here. Before creating the second base search this warning was not existing.

macadminrohit
Contributor

I think i found the mistake, I should be using the timer tokens only in the base search whereas i was using in all the sub searches 🙂

cmerriman
Super Champion

You're exactly right, @macadminrohit . Base searches only require earliest and latest in the base search itself and do not expect them to be called out in any of the searches referencing them. I will move your comment to an answer if you'd like to accept it and close out the question.

azdale
Engager

Hello,
I think the time picker should also be included in your base search. So that its something like this. What do you currently have?

"base search query"

$TimeRangePkr.earliest$

$TimeRangePkr.latest$

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...