Splunk Search

Token reference for TimeChart panel

synastraa
Path Finder

alt textalt text

Hi,

I am currently trying to do a drill down for my panel when i click on each month. However when I click on the month , the month retrieve was in epoch time format. How do i work around this so I can do drilldown for my timechart? Thanks

Best Regards,
Aloysius

Tags (1)
0 Karma
1 Solution

tiagofbmm
Influencer

You can use an eval token instead of the native "set" that Splunk UI uses.

    <drilldown>
      <set token="t">$click.value$</set>
      <eval token="t">strftime($click.value$,"%m")</eval>
    </drilldown>

This will set your token to the month number. For more info on date and times formats:

https://docs.splunk.com/Documentation/Splunk/7.1.1/SearchReference/Commontimeformatvariables

View solution in original post

tiagofbmm
Influencer

You can use an eval token instead of the native "set" that Splunk UI uses.

    <drilldown>
      <set token="t">$click.value$</set>
      <eval token="t">strftime($click.value$,"%m")</eval>
    </drilldown>

This will set your token to the month number. For more info on date and times formats:

https://docs.splunk.com/Documentation/Splunk/7.1.1/SearchReference/Commontimeformatvariables

synastraa
Path Finder

Thanks tiagofbmm,

this solved my question.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...