Dashboards & Visualizations

How to remove timezone from job.latestTime and job.earliestTime token?

BakaFon
Loves-to-Learn Everything

I need to add a line that show the number of results I get in the timeframe of the dashboard search using the job.earliestTime and job.latestTime tokens but if I use the replace function it doesn't work.

This is the code of the dashboard I used:

 

 

<html>
          <div class="custom-result-value">Results: $result$ in the time frame ($stime$ a $ltime$)</div>
        </html>
      <table id="test_table">
        <search>
          <query>| metadata type=sources | eval lastTime=strftime(lastTime, "%Y-%m-%d %H:%M:%S.%Q"), firstTime=strftime(firstTime, "%Y-%m-%d %H:%M:%S.%Q"), recentTime=strftime(recentTime, "%Y-%m-%d %H:%M:%S.%Q")</query>
          <earliest>-365d@d</earliest>
          <latest>now</latest>
          <sampleRatio>1</sampleRatio>
          <progress>
            <eval token="result">tonumber('job.resultCount')</eval>
            <eval token="ltime">tostring('job.latestTime')</eval>
            <eval token="stime">tostring('job.earliestTime')</eval>
            <eval token="stime">replace('$stime$',"\+\d+:00","")</eval>
            <eval token="stime">replace('$ltime$',"\+\d+:00","")</eval>
          </progress>
        </search>
        <option name="count">10</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">none</option>
        <option name="percentagesRow">false</option>
        <option name="rowNumbers">true</option>
        <option name="totalsRow">false</option>
        <option name="wrap">true</option>
      </table>

 

 

I get this regardless or not i use the replace command

BakaFon_0-1644327212342.png

The replace command works if used in a regular search

BakaFon_1-1644327699104.png

 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...