Splunk Search

Eval strftime not working with Linked Search

Jack_Accent
Loves-to-Learn

Hello! Still very new to Splunk so hoping to get some clarification.

My dashboard is currently using a post-process search as its base and filtering data from there. On my dashboard objects, I have a <link></link> which works fine until adding an eval strftime to convert the time to human readable.

Running this search as a new search manually with the eval works fine. However, the link directs to a blank search. Removing the eval statement makes the link work.

Link:
<link target="_blank">

search?q=| inputlookup io_vuln_data_lookup where $severity$ | search last_found &gt;= "$info_min_time$" AND last_found &lt;= "$info_max_time$"

| eval last_found = strftime(last_found, "%c")

| table dns_name,  last_found | where lower(state)!="fixed"

</link>

I was hoping to only do this conversion for a single dashboard object, so didn't want to convert the entire lookup. Would be amazing if I could get this search to work 🙂

Thanks!

Labels (3)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

In SimpleXML, certain characters must be entered with HTML entities. (Specifically, double quotes, greater than, less than, and so on.)  More generally, GET URLs are best encoded without special characters.  So, replace | eval last_found = strftime(last_found, "%c") with

%3D%20strftime(last_found%2C%20%22%25c%22)

 Meanwhile I do not know how the cited URL could "works fine till."  If you are entering these in source editor, you can try replacing double quotes with &quot;, i.e.,

| eval last_found = strftime(last_found, &quot;%c&quot;)

I recommend using the visual editor, however.  There, you can enter SPL as SPL.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...