Hi
In my dashboard I have a lot of the following timestamps
at the beginning of I have a timepicker
<input type="time" token="field1" searchWhenChanged="true">
<label>Time Intervall</label>
<default>
<earliest>-6h@h</earliest>
<latest>@h</latest>
</default>
<change>
<eval token="time1">strftime(relative_time(now(),$field1.earliest$),"%c")</eval>
<eval token="time2">strftime(relative_time(now(),$field1.latest$),"%c")</eval>
</change>
</input>
This is documented in:
http://docs.splunk.com/Documentation/Splunk/6.3.2/Viz/tokens#Access_labels_and_values_of_form_inputs
Giving the following results:
Signing successful for merchant 12025 June 22, 2016 12:00 AM to July 2, 2016 12:00 AM
The problem is:
When opening dashboard it does not pick default, it just seem to have two based on now():
Signing successful for merchant 65536 July 1, 2016 12:38 PM to July 1, 2016 12:38 PM
If I change any of the merchant or resolution dropdowns I get the correct timestamp.
But if I change the timepicker which uses the timepicker applet. it is not cached up, showing no changes.
If I change any of the other dropdowns the change is picked up.
... View more