So on the GUI I have been looking at the various time pickers . . . specifically "Date & Time" and "Advanced".
I see advanced in particular can do limited arithmetic (@d-1m), etc.
Basically, what I am hoping for, is for the user to cut a date/time out of a log, then come to say "Advanced" and do the following:
In Earliest have something prepopulated like lastest-2m
and in Latest
paste the copied value.
Now I realize the same could be accomplished with "Date&Time", except the date needs to be pasted twice and then earliest needs to be played with by hand.
I am hoping to get this down to a single paste and no hand editing . . . just paste and search.
Is that possible?
Frank
This can be done by creating your own form
:
http://docs.splunk.com/Documentation/Splunk/6.4.0/Viz/FormEditor
http://docs.splunk.com/Documentation/Splunk/6.4.0/Viz/Buildandeditforms
Interesting . . . I'll check it out. Thank you.