Splunk Search

Timechart not passing span value to drilldown

Communicator

Hi Guys,

I'm using a token in my search to drill down on a click.name2, which tells me success/failure tallies broken down by 1 day spans.

The problem is, it isn't passing the 1d timespan to the new panel. It is using the original timespan. I tried passing the $earliest$ and $latest$ tokens to the new panel, but it is using the original panels time still. Is there an easier way to do this?

0 Karma
1 Solution

Communicator

Figured it out: I inadvertently renamed _time to Date and ran a strftime function on it. This confuses the splunk. I removed the time transforms and it passes the day down as normal.

View solution in original post

0 Karma

Communicator

Figured it out: I inadvertently renamed _time to Date and ran a strftime function on it. This confuses the splunk. I removed the time transforms and it passes the day down as normal.

View solution in original post

0 Karma

Communicator

Not sure if the other panel has been set to use the same time picker which your first panel is using.

0 Karma

Communicator

Not using any time pickers, I hard coded the first timespan into the query

0 Karma