Splunk Search

How to create a count down?

Anesthet1ze
Explorer

Hello, 

 

I need to create a single value panel that displays a countdown from today's date until a target date, how can I achieve this?  Right now I am using sample data and I added a field called "GoLiveDate" to the data and put the target date in (which is in the future.) What I want to do is put a panel in that says something like "80 days until Go Live."  Then tomorrow it would say "79 days until Go Live" etc etc -  Is something like this possible?

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Subtract the current date from the go-live date and divide by 86400 to get the number of days.

 

| eval days = (strptime(GoLiveDate, "<<format string>>") - now()) / 86400

 

where <<format string>> describes the format of the GoLiveDate value.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Subtract the current date from the go-live date and divide by 86400 to get the number of days.

 

| eval days = (strptime(GoLiveDate, "<<format string>>") - now()) / 86400

 

where <<format string>> describes the format of the GoLiveDate value.

---
If this reply helps you, Karma would be appreciated.

Anesthet1ze
Explorer

Thanks so much for your answer,  I'm getting an eval statement malformed, here is the query:

Apologies the field is called GoLive.

| eval days = ((strptime(GoLive, "%Y/%m/%d") - now())/86400

the GoLive field in my data is formatted as such:  20221120

Trying to get it to come up in a single value but it's unhappy with what I did.  Apologies, still learning.

 

0 Karma

Anesthet1ze
Explorer

Alright, sorry I got the eval statement to work, it was a bracket issue.. but the result I'm getting is not what I'm looking for it's showing 20,221,120 I'm looking for it to say 80 

0 Karma

Anesthet1ze
Explorer

Me again! I figured it out, for some reason had to use the table to get it to display properly.. Splunk is still a mystery to me.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...