The same principle applies for all 'tokens' you want to pass in to the Splunk dashboard, they are just url parameters prefixed with 'form.'. For example this url https://yoursplunkhost/en-GB/app/app_name/dashboard?form.time_range.earliest=-30d%40d&form.time_range.latest=now&form.level=*&form.first_token=ValueOfFirstToken&form.second_token=ValueOfSecondToken will set the time picker token 'time_range' for earliest=-30d@d latest=now and it will set the token named 'first_token' and 'second_token' as above. Sorting is just managed in the search. By default Splunk will show you indexed events in reverse chronological order, so depending on what visualisation you are doing, you may not need to do any sorting, but Splunk sort is in a simple form | sort fieldname but check the docs for full details https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Sort
... View more