Splunk Search

Real-time Dashboard

hjwang
Contributor

Hi~there

Does anyone know if real-time search on dashboard can display last accumulated results such as last -1h when entering the view(for graph or resulting table), because i found every time i enter the dashboard, it run the search from that time. That is to say it accumulate from zero result(like non-schedule saved search). we use vesion 4.1.8

Thanks in advance.

Tags (1)
0 Karma
1 Solution

Ayn
Legend

No, not currently possible, though there are workarounds that you can try. See the answers to this question: http://splunk-base.splunk.com/answers/24641/populate-initial-realtime-chart-with-historical-data

View solution in original post

0 Karma

Ayn
Legend

No, not currently possible, though there are workarounds that you can try. See the answers to this question: http://splunk-base.splunk.com/answers/24641/populate-initial-realtime-chart-with-historical-data

0 Karma

hjwang
Contributor

I got it, thanks

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...