Dashboards & Visualizations

Why is my dashboard query ignoring timepicker selected default values?

  <label>SYBASE TEST</label>
  <searchTemplate><My Search></searchTemplate>
  <fieldset submitButton="true">
        <input type="time" token="field1"><label></label><default><earliestTime>-1d@d</earliestTime><latestTime>@d</latestTime></default></input></fieldset>
            <table><searchPostProcess<My PostProcess 1></searchPostProcess><option name="wrap">true</option>
                <option name="rowNumbers">true</option>
                <option name="dataOverlayMode">none</option>
                <option name="drilldown">row</option>
                <option name="count">30</option>
                    <condition field="SERVER">
                        <set token="SERVER">$click.value$</set>
            <table depends="$SERVER$">
                <title>SERVER BACKUP : $SERVER$</title>
                <searchPostProcess><My Post Process 2></searchPostProcess>
                <option name="wrap">true</option>
                <option name="rowNumbers">false</option>
                <option name="dataOverlayMode">none</option>
                <option name="drilldown">row</option>
                <option name="count">30</option>

Even though I have my timepicker defaulted to "Yesterday" data, when the search is executed, it is still considering "All Time" for search execution. Could someone help me with where I am doing it wrong??


0 Karma


I see in your code you are using searchPostProcess, that mean you are have searchTemplate define (you haven't put in the question).

So for the searchTemplate, add following lines (As said bu chabfoli)
< earliestTime >$field1.earliest$< /earliestTime >
< latestTime >$field1.latest$< /latestTime >

Secondly, remove the < earliest > and < latest > tags for the searchPostProcess (which are just below searchPostProcess line in your example.. i.e line #24 as indicated).

0 Karma


Hello, to get the picker time, try adding the following inside the each element with a search or search post process:

Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...