Splunk Search
Highlighted

Search Language variable for search duration

Path Finder

Hello,
I was curious if there was a way to reference a search duration for use within the search? Primarily for use inside a dashboard. If the timepicker selects a 5 day duration then the search string could have a variable which would be the value from the timepicker in seconds (so for 5 days the value would be 432000 seconds). I'm not sure if this is possible without adding apps/custom modules.

Thank you for any help!

Tags (2)
Highlighted

Re: Search Language variable for search duration

SplunkTrust
SplunkTrust

Yes, using addinfo and eval. addinfo will add four timet fields -- `infomintimeandinfomaxtime` being the useful ones for your purpose. Considering they are both timet, duration is just a matter of arithmetic.

my_search | addinfo | eval tpwindow=info_max_time - info_min_time

http://www.splunk.com/base/Documentation/latest/SearchReference/Addinfo

Highlighted

Re: Search Language variable for search duration

Motivator

You just saved my day dwaddle, thx

0 Karma