Splunk Enterprise

help on timechart click value

jip31
Motivator

hello

I use a click value token on my timechart in order to display details

it works but now what I need is when I click on a specific bar of my timechart (it means a bar for a specific day) I need to display only the data for this date

how to do this please

<search>
          <query>index=tutu sourcetype=toto ezconf=$ezconf$ 
| timechart span=1d count(hang)as hang</query>
          <earliest>-7d@h</earliest>
          <latest>now</latest>
        </search>
        <drilldown>
          <set token="hang">$click.value$</set>
        </drilldown>
      </chart>
    </panel>
  </row>
  <row>
    <panel depends="$hang$">
      <title></title>
      <table>
        <title></title>
        <search>
          <query>index=toto sourcetype=tutu ezconf=$ezconf$ 
| eval time = strftime(_time, "%d-%m-%y %H:%M") 
| sort - time 
| table time hang</query>
          <earliest>-7d@h</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </table>
    </panel>

 

Tags (1)
0 Karma
1 Solution

tscroggins
Influencer

@jip31 

The earliest and latest values are available as tokens:

<drilldown>
  <set token="earliest_tok">$earliest$</set>
  <set token="latest_tok">$latest$</set>
</drilldown>

You can use these tokens in your other visualization searches:

<search>
  <query>index=toto sourcetype=tutu ezconf=$ezconf$ 
| eval time = strftime(_time, "%d-%m-%y %H:%M") 
| sort - time 
| table time hang</query>
  <earliest>$earliest_tok$</earliest>
  <latest>$latest_tok$</latest>
</search>

You can initialize earliest_tok and latest_tok to default values using a time input or a combination of <init> and <set> tags.

View solution in original post

0 Karma

tscroggins
Influencer

@jip31 

The earliest and latest values are available as tokens:

<drilldown>
  <set token="earliest_tok">$earliest$</set>
  <set token="latest_tok">$latest$</set>
</drilldown>

You can use these tokens in your other visualization searches:

<search>
  <query>index=toto sourcetype=tutu ezconf=$ezconf$ 
| eval time = strftime(_time, "%d-%m-%y %H:%M") 
| sort - time 
| table time hang</query>
  <earliest>$earliest_tok$</earliest>
  <latest>$latest_tok$</latest>
</search>

You can initialize earliest_tok and latest_tok to default values using a time input or a combination of <init> and <set> tags.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...