Splunk Search

Real-time Dashboard

hjwang
Contributor

Hi~there

Does anyone know if real-time search on dashboard can display last accumulated results such as last -1h when entering the view(for graph or resulting table), because i found every time i enter the dashboard, it run the search from that time. That is to say it accumulate from zero result(like non-schedule saved search). we use vesion 4.1.8

Thanks in advance.

Tags (1)
0 Karma
1 Solution

Ayn
Legend

No, not currently possible, though there are workarounds that you can try. See the answers to this question: http://splunk-base.splunk.com/answers/24641/populate-initial-realtime-chart-with-historical-data

View solution in original post

0 Karma

Ayn
Legend

No, not currently possible, though there are workarounds that you can try. See the answers to this question: http://splunk-base.splunk.com/answers/24641/populate-initial-realtime-chart-with-historical-data

0 Karma

hjwang
Contributor

I got it, thanks

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...