Dashboards & Visualizations

timerange for the history command

paulathome
Path Finder

I've noticed that running the "| history" command will return different results based on the setting of the timerangepicker. So my question is how can I define the earliest and latest values within the search bar, or in a dashboard panel's query?

| history earliest=-24h                 does not work
earliest=-24h | history                 does not work

and I'm fairly confident that anything downstream from the history command won't be able to influence how many results were delivered initially by the history command.

0 Karma
1 Solution

paulathome
Path Finder

I was using this in a dashboard panel to nicely display the last few searches that a user performed and I was able to set the earliest and latest in the Search module. Couple that with a Pager, Table, HTML and a redirector module I was all set.

Thanks Sideview Utils,
Paul

View solution in original post

0 Karma

somesoni2
SplunkTrust
SplunkTrust

You would not be able to add earliest or latest value in a query (within search bar or a dashboard query) involving '|history'. The only option is the use timerangepicker (from searchbar) or from param "earliest" or latest within dashboard xml.

paulathome
Path Finder

I was using this in a dashboard panel to nicely display the last few searches that a user performed and I was able to set the earliest and latest in the Search module. Couple that with a Pager, Table, HTML and a redirector module I was all set.

Thanks Sideview Utils,
Paul

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...