Splunk Enterprise

How to pass latest time in a drill down

james_n
Path Finder

Hi,

I am facing a problem while passing latest value to drill down form, So when I click on each row i want the drill to show the transactions in that time range alone dynamically.

Spoiler

 

<dashboard>
<label>Sample</label>
<row>
<panel>
<chart>
<search>
<query>index=_internal | timechart count by sourcetype</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<option name="charting.chart">column</option>
<option name="charting.drilldown">all</option>
<drilldown>
<set token="name2">$click.name2$</set>
<eval token="ear">$click.value$</eval>
<eval token="lat">relative_time($click.value$,"+59m")</eval>
</drilldown>
</chart>
</panel>
</row>
<row>
<panel>
<chart>
<title>$name2$</title>
<search>
<query>index=_internal sourcetype=$name2$ | timechart span=1m count</query>
<earliest>$ear$</earliest>
<latest>$lat$</latest>
</search>
<option name="charting.chart">line</option>
<option name="charting.drilldown">none</option>
</chart>
</panel>
</row>
</dashboard>

Above dashboard working fine as expected but if select more then 24 hours getting a problem.

Expected result:

If i select <= 24 hours, latest time value should be  i.e,

Spoiler
<eval token="lat">relative_time($click.value$,"+59m")</eval>

same like 7 days - "+1d", 30days  - "+7d", YeartoDate - "+1mon"

Please help me on this. Thanks in advance.

 

 

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...