Splunk Enterprise

help on base search time modifier

jip31
Motivator

hi

 

as you can see I use a base search in order to dis play two single pnels, one on the last 24 h and one on the last 7 days

so for the second panel I need to put the time range on the last 7 days

I have done this but it doesn't works :

<earliest>-7d@d</earliest>
          <latest>now</latest>

 

  <row>
    <panel>
      <title>Incidents ouverts</title>
      <single>
        <title>Intervalle de remps : 24 dernières heures</title>
        <search id="countsite">
          <query>`index_mes` sourcetype=sig sig_app="$site$" 
| stats dc(sig_id)</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
        <option name="height">200</option>
        <option name="rangeColors">["0x53a051","0xf8be34","0xf1813f","0xdc4e41"]</option>
        <option name="rangeValues">[0,5,10]</option>
        <option name="refresh.display">progressbar</option>
        <option name="useColors">1</option>
      </single>
    </panel>
    <panel>
      <title>Incidents ouverts</title>
      <single>
        <title>Intervalle de remps : 7 derniers jours</title>
        <search base="countsite">
          <query>
| stats dc(sig_id)</query>
      

what is the problem please?

 

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

The base search has to cover the widest time range

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
<query>`index_mes` sourcetype=sig sig_app="$site$" 
| where _time>=relative_time(now(),"-24h@h")
| stats dc(sig_id)</query>

You can't change the time period of the search - try filtering (assuming the base query still has the data you need)

0 Karma

jip31
Motivator

sorry but its not the aim of my question

I use a base search in order to avoid to reuse the code below in my second search

`index_mes` sourcetype=sig sig_app="$site$" 

But in this second search, the time range of the single panel has to be on the last 7 days instead on the last 24 h

But I dont how to specify it in the code....

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The base search has to cover the widest time range

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...