Splunk Search

How to create a count down?

Anesthet1ze
Explorer

Hello, 

 

I need to create a single value panel that displays a countdown from today's date until a target date, how can I achieve this?  Right now I am using sample data and I added a field called "GoLiveDate" to the data and put the target date in (which is in the future.) What I want to do is put a panel in that says something like "80 days until Go Live."  Then tomorrow it would say "79 days until Go Live" etc etc -  Is something like this possible?

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Subtract the current date from the go-live date and divide by 86400 to get the number of days.

 

| eval days = (strptime(GoLiveDate, "<<format string>>") - now()) / 86400

 

where <<format string>> describes the format of the GoLiveDate value.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Subtract the current date from the go-live date and divide by 86400 to get the number of days.

 

| eval days = (strptime(GoLiveDate, "<<format string>>") - now()) / 86400

 

where <<format string>> describes the format of the GoLiveDate value.

---
If this reply helps you, Karma would be appreciated.

Anesthet1ze
Explorer

Thanks so much for your answer,  I'm getting an eval statement malformed, here is the query:

Apologies the field is called GoLive.

| eval days = ((strptime(GoLive, "%Y/%m/%d") - now())/86400

the GoLive field in my data is formatted as such:  20221120

Trying to get it to come up in a single value but it's unhappy with what I did.  Apologies, still learning.

 

0 Karma

Anesthet1ze
Explorer

Alright, sorry I got the eval statement to work, it was a bracket issue.. but the result I'm getting is not what I'm looking for it's showing 20,221,120 I'm looking for it to say 80 

0 Karma

Anesthet1ze
Explorer

Me again! I figured it out, for some reason had to use the table to get it to display properly.. Splunk is still a mystery to me.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...