Splunk Search

Search Language variable for search duration

Path Finder

I was curious if there was a way to reference a search duration for use within the search? Primarily for use inside a dashboard. If the timepicker selects a 5 day duration then the search string could have a variable which would be the value from the timepicker in seconds (so for 5 days the value would be 432000 seconds). I'm not sure if this is possible without adding apps/custom modules.

Thank you for any help!

Tags (2)


Yes, using addinfo and eval. addinfo will add four time_t fields -- info_min_time and info_max_time being the useful ones for your purpose. Considering they are both time_t, duration is just a matter of arithmetic.

my_search | addinfo | eval tpwindow=info_max_time - info_min_time



You just saved my day dwaddle, thx

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!