Splunk Search

Get single value panel to display a "date"

mjm295
Path Finder

Hi

I have search for a dashboard which produces a graph and does predictions, I want to display the date when we expect a certain threshold to be crossed. I have added some smarts to the search so it now ends with

| eval DATE=if('high(future)' > "3.9", _time, null()) | search DATE!=null() | head 1 | fields _time 

This gives me the date I require but in a stats table. How can I display it bigger such as a single value panel?

Thanks
Mark

0 Karma

cmerriman
Super Champion

just doing this and putting it as a single values panel should work: | eval DATE=if('high(future)' > "3.9", strftime(_time, "%Y %m %d"), null())|where isnotnull(DATE)|head 1|fields DATE or you can use |table DATE and put it in an html panel with <h2> node for a header possibly to make it larger print.

mjm295
Path Finder

| eval DATE=if('high(future)' > "3.9", _time, null()) | search DATE!=null() | head 1 | fields _time | eval mytime=strftime(_time, "%Y %m %d") | table mytime

That worked - any better options?

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @mjm295, if @cmerriman's solution worked then please don't forget to accept her answer to award karma points and close the question. 🙂

0 Karma
Get Updates on the Splunk Community!

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Community Content Calendar, October Edition

Welcome to the October edition of our Community Spotlight! The Splunk Community is a treasure trove of ...