Splunk Search

How to create a count down?

Anesthet1ze
Explorer

Hello, 

 

I need to create a single value panel that displays a countdown from today's date until a target date, how can I achieve this?  Right now I am using sample data and I added a field called "GoLiveDate" to the data and put the target date in (which is in the future.) What I want to do is put a panel in that says something like "80 days until Go Live."  Then tomorrow it would say "79 days until Go Live" etc etc -  Is something like this possible?

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Subtract the current date from the go-live date and divide by 86400 to get the number of days.

 

| eval days = (strptime(GoLiveDate, "<<format string>>") - now()) / 86400

 

where <<format string>> describes the format of the GoLiveDate value.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Subtract the current date from the go-live date and divide by 86400 to get the number of days.

 

| eval days = (strptime(GoLiveDate, "<<format string>>") - now()) / 86400

 

where <<format string>> describes the format of the GoLiveDate value.

---
If this reply helps you, Karma would be appreciated.

Anesthet1ze
Explorer

Thanks so much for your answer,  I'm getting an eval statement malformed, here is the query:

Apologies the field is called GoLive.

| eval days = ((strptime(GoLive, "%Y/%m/%d") - now())/86400

the GoLive field in my data is formatted as such:  20221120

Trying to get it to come up in a single value but it's unhappy with what I did.  Apologies, still learning.

 

0 Karma

Anesthet1ze
Explorer

Alright, sorry I got the eval statement to work, it was a bracket issue.. but the result I'm getting is not what I'm looking for it's showing 20,221,120 I'm looking for it to say 80 

0 Karma

Anesthet1ze
Explorer

Me again! I figured it out, for some reason had to use the table to get it to display properly.. Splunk is still a mystery to me.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...