Dashboards & Visualizations

Why are the two base searches throw warnings in a dashboard?

macadminrohit
Contributor

I have two base searches in a dashboard, not sure if that is at all possible. But as soon as i use the second base search created, i get warnings with this :

$timer.earliest$
$timer.latest$

Warning is : Unknown node is not allowed here. Before creating the second base search this warning was not existing.

macadminrohit
Contributor

I think i found the mistake, I should be using the timer tokens only in the base search whereas i was using in all the sub searches 🙂

cmerriman
Super Champion

You're exactly right, @macadminrohit . Base searches only require earliest and latest in the base search itself and do not expect them to be called out in any of the searches referencing them. I will move your comment to an answer if you'd like to accept it and close out the question.

azdale
Engager

Hello,
I think the time picker should also be included in your base search. So that its something like this. What do you currently have?

"base search query"

$TimeRangePkr.earliest$

$TimeRangePkr.latest$

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...