Splunk Search

Search Language variable for search duration

aputz
Path Finder

Hello,
I was curious if there was a way to reference a search duration for use within the search? Primarily for use inside a dashboard. If the timepicker selects a 5 day duration then the search string could have a variable which would be the value from the timepicker in seconds (so for 5 days the value would be 432000 seconds). I'm not sure if this is possible without adding apps/custom modules.

Thank you for any help!

Tags (2)

dwaddle
SplunkTrust
SplunkTrust

Yes, using addinfo and eval. addinfo will add four time_t fields -- info_min_time and info_max_time being the useful ones for your purpose. Considering they are both time_t, duration is just a matter of arithmetic.

my_search | addinfo | eval tpwindow=info_max_time - info_min_time

http://www.splunk.com/base/Documentation/latest/SearchReference/Addinfo

chris
Motivator

You just saved my day dwaddle, thx

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...