Getting Data In

How to configure time picker for dashboard in Enterprise Security?

splunky_diamond
Path Finder

Hello Splunkers!

In the Security Posture by default there are no filters that would allow us to adjust the time, meaning, we see the summary about notable events over the last 24 hours. I want to change that, I have added a time picker that I would like to bind to one dashboard in the security posture - "Key indicators" so that I can see for example the summary of notable events over the last 12 hours or 7 days. Can someone please explain what needs to be done on time picker or dashboard in order to achieve this, or maybe is there an easier way to do this? 

splunky_diamond_0-1715666294339.png


Thanks for taking your time reading and replying to my post ❤️

Labels (2)
0 Karma
1 Solution

Temuulen0303
Explorer

yes you are doing it right.
After adding time picker you can click on this icon:


Temuulen0303_0-1715671874836.png


and
1) select edit on your query
2) Go to "Time Range"
3) Click on Input and select your Time picker token

View solution in original post

Temuulen0303
Explorer

yes you are doing it right.
After adding time picker you can click on this icon:


Temuulen0303_0-1715671874836.png


and
1) select edit on your query
2) Go to "Time Range"
3) Click on Input and select your Time picker token

splunky_diamond
Path Finder

Hello @Temuulen0303 , 

Thanks for taking your time replying to my post!

I checked, it is only applicable to search "notable event by urgency", as for the saved searches, there is no option to choose the time range:

splunky_diamond_0-1715683937483.pngsplunky_diamond_1-1715683976417.png

splunky_diamond_2-1715684037644.png

 

Also, for some reason when I linked the time range with "notable events by urgency" when I select the custom time, it does not apply for some reason... I checked in the source code of that search, the query for the earliest and latest time, it does take it from my time picker that I added. 

splunky_diamond
Path Finder

Update: it actually did work! I just opened the dashboard in a search and the time-picker is indeed applied.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...