Splunk Enterprise

Timerange picker: Change the value from _time to Reported date

vivek_manoj
Explorer

Hi All,

Thanks in advance.

By default time range picker is using _time. I want to change the value of time range picker value from _time to reported_date.

So, please help me out.

Tags (1)
0 Karma

woodcock
Esteemed Legend

It can be done but it is nasty. You must expand the timepicked range a bit ( myBufferSeconds ) to make sure that you capture the all the events with the other time values because obviously the other time field ( MyOtherEpochDateField ) has different values than _time does (or you wouldn't be asking this).

index=YouShouldAlwaysSpecifyAnIndex sourcetype=AndSourcetypeToo
    [| makeresults
    | addinfo
    | eval myBufferSeconds = 5*24*60*60
    | eval search="earliest=" . round((info_min_time - myBufferSeconds),0) . " latest=" . round((info_max_time + myBufferSeconds), 0)
    | table search]
    MyOtherEpochDateField>=
    [| makeresults
    | addinfo
    | return $info_min_time] AND
    MyOtherEpochDateField<=
    [| makeresults
    | addinfo
    | return $info_max_time]

If your MyOtherEpochDateField is not a time_t (AKA epoch) then you have to do even more work and you can no longer template your base search and have to pull all the events in and use a | eval MyOtherEpochDateField=strptime(MyOtherEpochDateField, "%some%time%format%here") | search MyOtherEpochDateField ....

0 Karma

niketn
Legend

@vivek_manoj, this can be done but will have performance impact on your dashboard/s. You should consider event timestamp to pick _time from reported_date during data ingestion if you want to build dashboard/s on reported_date.

Can you add some sample events with examples of reported_date? Also what is the field/value behind extraction of event timestamp (_time)?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...