Getting Data In

on Splunk 5.0

KShen
New Member

How to add date time range to the dashboard on the Splunk 5.0

Tags (1)
0 Karma

lguinn2
Legend

In Splunk 5, you will probably need to use Advanced XML to do what you want. Here is a link to the 5.0 documentation:

Build a dashboard using advanced XML

However, I found this Example app much more useful Splunk Dashboard Examples for 5.0. It's free and it shows a lot of advanced XML code...

0 Karma

KShen
New Member

"probably need to do" is not answer.

0 Karma

lguinn2
Legend

You are right, but then I thought perhaps that the advice in the duplicate question:

Do dashboards in Splunk 5.0 support dynamic date/time inputs?

didn't work for you. That question clearly pointed to the answer in the manual

Build and edit forms with simple XML

Did you read that and do what it suggested?

0 Karma

KShen
New Member

I read the http://docs.splunk.com/Documentation/Splunk/5.0/Viz/Buildandeditforms

and try and datetime picker is not displayed. And I do not know how to pass the earliest and last time to the querystring. Any idea?

Monthly OR Data

error

  <!-- Create a text box; token is "series"                         -->
  <!-- label: Label for the text box                                -->
  <!-- default: A default value is not specified                    -->
  <!-- seed: Upon first load, the text box specifies 'splunkd'      -->
  <!-- suffix: All tokens are followed by a *                       -->
  <!--         If user does not specify text, then search uses '*'  -->
  <input type="text" token="series">
    <label>sourcetype</label>
    <default></default>
    <seed>splunkd</seed>
    <suffix>*</suffix>
  </input>

  <!-- Add default TimePicker -->
  <input type="time" />





<table>

  <searchString>error</searchString>
  <title></title>

</table>
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...