Dashboards & Visualizations

Why are the two base searches throw warnings in a dashboard?

macadminrohit
Contributor

I have two base searches in a dashboard, not sure if that is at all possible. But as soon as i use the second base search created, i get warnings with this :

$timer.earliest$
$timer.latest$

Warning is : Unknown node is not allowed here. Before creating the second base search this warning was not existing.

macadminrohit
Contributor

I think i found the mistake, I should be using the timer tokens only in the base search whereas i was using in all the sub searches 🙂

cmerriman
Super Champion

You're exactly right, @macadminrohit . Base searches only require earliest and latest in the base search itself and do not expect them to be called out in any of the searches referencing them. I will move your comment to an answer if you'd like to accept it and close out the question.

azdale
Engager

Hello,
I think the time picker should also be included in your base search. So that its something like this. What do you currently have?

"base search query"

$TimeRangePkr.earliest$

$TimeRangePkr.latest$

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...