Splunk Search

Run single search multiple times with different timeframes

p_basanth
New Member

I have a saved search named "myquery1". I want run this search 3 times (-60m@m, -4h@h and -12h@h).
The above outputs will be displayed in 3 panels of my dashboard
Errors in past 1 hour
Errors in past 4 hours
Errors in past 12 hours.
How can i create 1 search and specify time window in the panel?

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could run one search -12h@m and use three PostProcess modules to fix each timerange.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...