Dashboards & Visualizations

Post-process search with time picker to chance only effect one panel/search

johnansett
Communicator

Hello, not sure if this can be done, but figured I'd ask.

I have a dashboard with 4 base searches. I a row of tables which are post processed off them, which then drill down to another row of tables which is post processed from the same base search and finally that drills down to timechart, also post-processed from the same base search.

What I want to do is show the last 24 hours for the tables (which is set earliest/latest on the base search) but I want a time picker to be able to extend the timechart time range as desired. Is this possible? How can I do this, without effecting the results of the tables?

I can post the code if necessary.

Thanks!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi johnansett,
I don't know if it's exactly what you want, but in Splunk Dashboard Examples ( https://splunkbase.splunk.com/app/1603/ ) there's a dashboard that could solve you need: "Pan and Zoom Chart Controls"
Using this dashboard you can use a panel to restrict time range for the other panels.
Bye.
Giuseppe

0 Karma

johnansett
Communicator

Thanks, but I'm trying to go the other way. The goal is the tables provide a 24 hour view on the tables but they want to change the time on the timechart to 7 days, 30 days, etc. to see if this is a trend.

I can do it by using a separate search to power the timechart but defeats the purpose of the post-processing optimisation.

0 Karma

gcusello
SplunkTrust
SplunkTrust

you could put another time picker (or a different input) in the second panel that uses the first Time Picker as default.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...