Splunk Search

Relative Time Value to Timepicker Latest

hypePG
Path Finder

Hey,

I got a dashboard with different panels. They are all controlled by a single timepicker.
Usually the timeranges a several weeks. In one of the panels I want an overview for the last 24 hours relative to the latest time.

For Example:

Time range picked via the picker:
01.03.2019-8.03.2019
24h Overview should display events for this range:
07.03.2019-8.03.2019

I tried working with tokens and different method to calculate the new earliest time but didnt get it to work.
I think it will be a simple fix but I jsut cant get it atm.

Thanks in advance.

Max

0 Karma

vnravikumar
Champion

Hi @hypePG

Try like in that panel with

<row>
    <panel>
      <table>
        <search>
          <query>index="_internal" |stats count</query>
          <earliest>-24h@h</earliest>
          <latest>$time.latest$</latest>
        </search>
        <option name="drilldown">none</option>
      </table>
    </panel>
  </row>
0 Karma

hypePG
Path Finder

hey,

thanks for your answer! tried this already, i get the error message:

Invalid latest_time: latest_time must be after earliest_time. 

regards,

max

0 Karma

vnravikumar
Champion

are you passing timepickers latest time?

0 Karma

hypePG
Path Finder

yes i am:

    <search>
      <query>search</query>
      <earliest>-24h@h</earliest>
      <latest>$timepicker.latest$</latest>
      <sampleRatio>1</sampleRatio>
    </search>
0 Karma

vnravikumar
Champion

what is the time range that you have selected?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...