Splunk Search

How to get an epoch time for $client_time.latest$

trapper_dave
Engager

Hi,

I have a dashboard with a dropdown form allowing users to select the time period they wish to analyse.

I am looking to capture the latest time token of the period in epoch format but I am running into issues.

I have found that if the end time is 'now', then I can use time() however this doesn't work for when the end time is in the past (i.e. yesterday, previous week or previous year).

Can anyone assist me in figuring this out?

Many thanks,

Dave

Labels (1)
Tags (3)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

@trapper_dave 

The technique is to set up a hidden panel with a search that uses the addinfo command to get the latest time for the search and then use a <done> clause to set tokens based on that epoch.

See the attached dashboard

<form>
  <label>Time Pickers 2</label>
  <fieldset submitButton="false"></fieldset>
  <row>
    <panel>
      <input type="time" token="client">
        <label>Select Time</label>
        <default>
          <earliest>-1d@d</earliest>
          <latest>@d</latest>
        </default>
      </input>
      <table depends="$show_hidden$">
        <title>This simple search - is hidden - but is used to calculate the relative time for the second table</title>
        <search>
          <query>| makeresults 
| addinfo
          </query>
          <earliest>$client.earliest$</earliest>
          <latest>$client.latest$</latest>
          <done>
            <set token="search_latest">$result.info_max_time$</set>
            <eval token="search_latest_fmt">strftime($result.info_max_time$, "%F %T")</eval>
          </done>
        </search>
      </table>
      <table>
        <search>
          <query>
            | makeresults
            | eval Selected_Time_Input=$client.latest|s$
            | eval Selected_Time_ISO=$search_latest_fmt|s$
            | eval Selected_Time_Epoch=$search_latest$
            | table Selected_Time_Input Selected_Time_ISO Selected_Time_Epoch
          </query>
        </search>
      </table>
    </panel>
  </row>
</form>

Hope this helps

View solution in original post

trapper_dave
Engager

This was perfect, thank you.

0 Karma

bowesmana
SplunkTrust
SplunkTrust

@trapper_dave 

Glad it helped you. Can you mark the answer as a solution for others.

Cheers

 

Tags (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

@trapper_dave 

The technique is to set up a hidden panel with a search that uses the addinfo command to get the latest time for the search and then use a <done> clause to set tokens based on that epoch.

See the attached dashboard

<form>
  <label>Time Pickers 2</label>
  <fieldset submitButton="false"></fieldset>
  <row>
    <panel>
      <input type="time" token="client">
        <label>Select Time</label>
        <default>
          <earliest>-1d@d</earliest>
          <latest>@d</latest>
        </default>
      </input>
      <table depends="$show_hidden$">
        <title>This simple search - is hidden - but is used to calculate the relative time for the second table</title>
        <search>
          <query>| makeresults 
| addinfo
          </query>
          <earliest>$client.earliest$</earliest>
          <latest>$client.latest$</latest>
          <done>
            <set token="search_latest">$result.info_max_time$</set>
            <eval token="search_latest_fmt">strftime($result.info_max_time$, "%F %T")</eval>
          </done>
        </search>
      </table>
      <table>
        <search>
          <query>
            | makeresults
            | eval Selected_Time_Input=$client.latest|s$
            | eval Selected_Time_ISO=$search_latest_fmt|s$
            | eval Selected_Time_Epoch=$search_latest$
            | table Selected_Time_Input Selected_Time_ISO Selected_Time_Epoch
          </query>
        </search>
      </table>
    </panel>
  </row>
</form>

Hope this helps

Get Updates on the Splunk Community!

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...

New This Month in Splunk Observability Cloud - Synthetic Monitoring updates, UI ...

This month, we’re delivering several platform, infrastructure, application and digital experience monitoring ...