Splunk Search

Search Language variable for search duration

Path Finder

I was curious if there was a way to reference a search duration for use within the search? Primarily for use inside a dashboard. If the timepicker selects a 5 day duration then the search string could have a variable which would be the value from the timepicker in seconds (so for 5 days the value would be 432000 seconds). I'm not sure if this is possible without adding apps/custom modules.

Thank you for any help!

Tags (2)


Yes, using addinfo and eval. addinfo will add four time_t fields -- info_min_time and info_max_time being the useful ones for your purpose. Considering they are both time_t, duration is just a matter of arithmetic.

my_search | addinfo | eval tpwindow=info_max_time - info_min_time



You just saved my day dwaddle, thx

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!