Dashboards & Visualizations

Set latest time to clicked event time and earliest is relative to that time

lisheridan
Explorer

I have a SimpleResultsTable configured for drilldown which dispatches several child searches that display some charts. I want the child searches to set the latest time as the event time for what was clicked and I want the earliest time to be 1 day before that event time.

For example, if you click on an event that occurred at 11/5/2011 12:30:00 I want the child searches to show events from 11/4/2011 12:30:00 to 11/5/2011 12:30:00.

Is it possible to do this with earliest and latest and intentions?

0 Karma

lisheridan
Explorer

I think it is something like the following:

starttime=relative_time($time$, "-1d@s") endtime=$time$

... if $time$ is passed by row drilldown and can be picked up by ConvertToIntention.

I haven't been able to get variations of this to work yet though.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...