Dashboards & Visualizations

drilldown not using correct time range

lsnow
Explorer

I'm trying to do a drilldown in simple XML that uses a link like this:

/app/appname/formname?form.token=Sitename

When the new chart launches, the search is running against all time and the URL has "earliest=0" in part of the URL, after the #:

http://splunkserver/en-US/app/appname/formname?form.token=Sitename#formname?form.token=Sitename&**ea...

Even if I specify "earliest=$earliest$&latest=$latest$" in the link from the original report, I see the correct times for earliest and latest before the # in the drilldown form URL, but I end up with "earliest=0" after the #, and the search defaults to "All Time". What am I missing?

Tags (1)
0 Karma
1 Solution

Leo
Splunk Employee
Splunk Employee

thank you for feedback. That is a known issue in versions 5.0/5.0.1. The fix will soon be available with release of 5.0.2.

View solution in original post

Leo
Splunk Employee
Splunk Employee

thank you for feedback. That is a known issue in versions 5.0/5.0.1. The fix will soon be available with release of 5.0.2.

jaywilwk
Engager

I have lately tried this again with my drilldown and I'm still getting the same result. I'm currently on splunk 6.0.3

0 Karma

jaywilwk
Engager

I've done the same thing on my drilldown and I'm getting the same result and I'm on splunk 5.0.5

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...