Splunk Search

Why am I Unable to use time for filtering events in the new dashboard?

_pravin
Communicator

Hi Community,

 

I have a dashboard that gives me an overview of the details.

_pravin_0-1655204129161.png

When I click on one of the rows it drives me to a different dashboard which takes time from this dashboard and performs a granular search within time limits based on parent ID. This search performs a search on a panel that shows no data at all.

_pravin_1-1655204458887.png

When I try to look at the SPL of the empty dashboard, I realise that the SPL does search on milliseconds. This search is within the range of 1 second.

_pravin_2-1655204549450.png

This search is driven by a data model acceleration which can accelerate only for seconds.

So if the change the time range for more than a second I get the desired results.

_pravin_3-1655204859767.png

 

To fix this issue, the only option I can think of is reconstructing the SPL without data models but that will slow down the search or manipulate the time range so that I can get the data.

Is there some other option which I can use to get the desired results?

Thanks in advance.

 

Regards,

Pravin

 

 

 

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...