Dashboards & Visualizations

Time range ignored in dashboard and saved queries

Spidergawd
New Member
host="hostname*" SUSPENDING earliest ="-1d@d" latest = "-1d@d+24h"  | timechart count span=1m

In a dashboard or as a saved query the specified time range is ignored.
The query works if input manually.
Why ?

Tags (1)
0 Karma

lguinn2
Legend

I wonder if this is caused by the user timezone setting. Each user account can choose their own timezone. There is also a default timezone.

When input manually, the user's setting will apply. When run in a dashboard or as a saved query, it might be based on the setting for the owner of the knowledge object.

I am not sure this is the problem, but I think you should check this out.

0 Karma

Spidergawd
New Member

We are running version 5.0.3, build 163460 , "@d", thanks for that, I had tried -0d@d as well.
When I say the time range is ignored, the end of the time range is in the current day.
I need to distribute a clean comparable report of "yesterday"
thanks

0 Karma

lguinn2
Legend

"-1d@d+24h" is the same as"@d" FWIW

Which version of Splunk are you running?

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...