Dashboards & Visualizations

Filtering a table by a bucket_time span

sarak
Observer

Hi!

I have a dashboard with two parts - a table based on an existing dataset, and a column chart based on this query:

 

| bucket _time span=day | stats count by _time

 

The full table code looks like this:

 

{
    "type": "splunk.column",
    "dataSources": {
        "primary": "..."
    },
    "title": "...",
    "options": {
        "x": "> primary | seriesByName('_time')",
        "y": "> primary | frameBySeriesNames('count')",
        "legendDisplay": "off",
        "xAxisTitleVisibility": "hide",
        "yAxisTitleText": "...",
        "showYAxisWithZero": true
    },
    "eventHandlers": [],
    "context": {},
    "showProgressBar": false,
    "showLastUpdated": false
}

 

I want a click on any column to filter the table based on global_time - if I click on March 22, it filters the table to only show records where the _time is Mar 22 00:00:00 to Mar 22 23:59:59. How do I do that?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...