Dashboards & Visualizations

Time range ignored in dashboard and saved queries

Spidergawd
New Member
host="hostname*" SUSPENDING earliest ="-1d@d" latest = "-1d@d+24h"  | timechart count span=1m

In a dashboard or as a saved query the specified time range is ignored.
The query works if input manually.
Why ?

Tags (1)
0 Karma

lguinn2
Legend

I wonder if this is caused by the user timezone setting. Each user account can choose their own timezone. There is also a default timezone.

When input manually, the user's setting will apply. When run in a dashboard or as a saved query, it might be based on the setting for the owner of the knowledge object.

I am not sure this is the problem, but I think you should check this out.

0 Karma

Spidergawd
New Member

We are running version 5.0.3, build 163460 , "@d", thanks for that, I had tried -0d@d as well.
When I say the time range is ignored, the end of the time range is in the current day.
I need to distribute a clean comparable report of "yesterday"
thanks

0 Karma

lguinn2
Legend

"-1d@d+24h" is the same as"@d" FWIW

Which version of Splunk are you running?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...