Dashboards & Visualizations

set earliest from string

kennethyeung
New Member

i have a dashboard, in the click.value will have a string value (e.g 20182010)
and then below have another line chart, but how can i put the token to that search

e.g
index=test earliest=$token_date$

i think the $token_date need to use strptime to convert and then pass to search. but how?
Thanks

Tags (2)
0 Karma

sashraf
New Member

Instead of having earliest=$token_date$ in your search, replace it with the following subsearch:

[| makeresults | eval thisdate="$token_date$" | eval earliest=strptime(thisdate, "%Y%d%m") | fields + earliest]

So your example search would instead look like this:

index=test [| makeresults | eval thisdate="$token_date$" | eval earliest=strptime(thisdate, "%Y%d%m") | fields + earliest]

This is all assuming the date format you have is YYYYDDMM which would translate to 20th October 2018 with your example of 20182010. If the date format will be YYYYMMDD then use this instead:

index=test [| makeresults | eval thisdate="$token_date$" | eval earliest=strptime(thisdate, "%Y%m%d") | fields + earliest]
0 Karma

niketn
Legend

Is it is table or chart that you are clicking to get 20182010 as click.value?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

hi @kennethyeung,

You can use strptime when you click on chart and set token_date. what is date format of 20182010?
Can you please share you sample dashboard xml?

kennethyeung
New Member

Thanks your suggestion, i should eval token instead of eval in the search
strftime(strptime($click.value$,"%Y%m%d"),"%m/%d/%Y:00:00:00")
and the in search

index=$tok_index$ earliest="$tok_date$"

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

So, have you resolved your issue?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...