Splunk Enterprise

How to pass latest time in a drill down

james_n
Path Finder

Hi,

I am facing a problem while passing latest value to drill down form, So when I click on each row i want the drill to show the transactions in that time range alone dynamically.

Spoiler

 

<dashboard>
<label>Sample</label>
<row>
<panel>
<chart>
<search>
<query>index=_internal | timechart count by sourcetype</query>
<earliest>-24h@h</earliest>
<latest>now</latest>
</search>
<option name="charting.chart">column</option>
<option name="charting.drilldown">all</option>
<drilldown>
<set token="name2">$click.name2$</set>
<eval token="ear">$click.value$</eval>
<eval token="lat">relative_time($click.value$,"+59m")</eval>
</drilldown>
</chart>
</panel>
</row>
<row>
<panel>
<chart>
<title>$name2$</title>
<search>
<query>index=_internal sourcetype=$name2$ | timechart span=1m count</query>
<earliest>$ear$</earliest>
<latest>$lat$</latest>
</search>
<option name="charting.chart">line</option>
<option name="charting.drilldown">none</option>
</chart>
</panel>
</row>
</dashboard>

Above dashboard working fine as expected but if select more then 24 hours getting a problem.

Expected result:

If i select <= 24 hours, latest time value should be  i.e,

Spoiler
<eval token="lat">relative_time($click.value$,"+59m")</eval>

same like 7 days - "+1d", 30days  - "+7d", YeartoDate - "+1mon"

Please help me on this. Thanks in advance.

 

 

0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...

Secure Your Future: Mastering Upgrade Readiness for Splunk 10

Spotlight: The Splunk Health Assistant Add-On  The Splunk Health Assistant Add-On is your ultimate companion ...

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...