Splunk Search

Why am I Unable to use time for filtering events in the new dashboard?

_pravin
Communicator

Hi Community,

 

I have a dashboard that gives me an overview of the details.

_pravin_0-1655204129161.png

When I click on one of the rows it drives me to a different dashboard which takes time from this dashboard and performs a granular search within time limits based on parent ID. This search performs a search on a panel that shows no data at all.

_pravin_1-1655204458887.png

When I try to look at the SPL of the empty dashboard, I realise that the SPL does search on milliseconds. This search is within the range of 1 second.

_pravin_2-1655204549450.png

This search is driven by a data model acceleration which can accelerate only for seconds.

So if the change the time range for more than a second I get the desired results.

_pravin_3-1655204859767.png

 

To fix this issue, the only option I can think of is reconstructing the SPL without data models but that will slow down the search or manipulate the time range so that I can get the data.

Is there some other option which I can use to get the desired results?

Thanks in advance.

 

Regards,

Pravin

 

 

 

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...