Hello,
I was curious if there was a way to reference a search duration for use within the search? Primarily for use inside a dashboard. If the timepicker selects a 5 day duration then the search string could have a variable which would be the value from the timepicker in seconds (so for 5 days the value would be 432000 seconds). I'm not sure if this is possible without adding apps/custom modules.
Thank you for any help!
Yes, using addinfo
and eval
. addinfo
will add four time_t fields -- info_min_time
and info_max_time
being the useful ones for your purpose. Considering they are both time_t, duration is just a matter of arithmetic.
my_search | addinfo | eval tpwindow=info_max_time - info_min_time
http://www.splunk.com/base/Documentation/latest/SearchReference/Addinfo
You just saved my day dwaddle, thx