Hi splunk comuniti!
I have a job in splunk. In "Edit Search" i have two fields - Earliest time and Latest time. How can i get tokens of this fields to use them in search query?
Pls try $time_token.earliest$ and $time_token.latest$ where time_token is the name of your token
Pls try $time_token.earliest$ and $time_token.latest$ where time_token is the name of your token
@lakshman239 but i don't know the name of time_token in job
I create a scheduled job and in "Edit search" tab i have two text input which is Earliest time and Latest time, and i don't know their tokens
@lakshman239 i found how to do this, the tokens name are dispatch.latest_time and dispatch.earliest_time
Glad it worked. Pls download the Splunk dashboard example app, if you haven't already, as it has tons of good examples like the one which you are after.