Dashboards & Visualizations

timerange for the history command

paulathome
Path Finder

I've noticed that running the "| history" command will return different results based on the setting of the timerangepicker. So my question is how can I define the earliest and latest values within the search bar, or in a dashboard panel's query?

| history earliest=-24h                 does not work
earliest=-24h | history                 does not work

and I'm fairly confident that anything downstream from the history command won't be able to influence how many results were delivered initially by the history command.

0 Karma
1 Solution

paulathome
Path Finder

I was using this in a dashboard panel to nicely display the last few searches that a user performed and I was able to set the earliest and latest in the Search module. Couple that with a Pager, Table, HTML and a redirector module I was all set.

Thanks Sideview Utils,
Paul

View solution in original post

0 Karma

somesoni2
Revered Legend

You would not be able to add earliest or latest value in a query (within search bar or a dashboard query) involving '|history'. The only option is the use timerangepicker (from searchbar) or from param "earliest" or latest within dashboard xml.

paulathome
Path Finder

I was using this in a dashboard panel to nicely display the last few searches that a user performed and I was able to set the earliest and latest in the Search module. Couple that with a Pager, Table, HTML and a redirector module I was all set.

Thanks Sideview Utils,
Paul

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...