Splunk Enterprise

Timerange picker: Change the value from _time to Reported date

vivek_manoj
Explorer

Hi All,

Thanks in advance.

By default time range picker is using _time. I want to change the value of time range picker value from _time to reported_date.

So, please help me out.

Tags (1)
0 Karma

woodcock
Esteemed Legend

It can be done but it is nasty. You must expand the timepicked range a bit ( myBufferSeconds ) to make sure that you capture the all the events with the other time values because obviously the other time field ( MyOtherEpochDateField ) has different values than _time does (or you wouldn't be asking this).

index=YouShouldAlwaysSpecifyAnIndex sourcetype=AndSourcetypeToo
    [| makeresults
    | addinfo
    | eval myBufferSeconds = 5*24*60*60
    | eval search="earliest=" . round((info_min_time - myBufferSeconds),0) . " latest=" . round((info_max_time + myBufferSeconds), 0)
    | table search]
    MyOtherEpochDateField>=
    [| makeresults
    | addinfo
    | return $info_min_time] AND
    MyOtherEpochDateField<=
    [| makeresults
    | addinfo
    | return $info_max_time]

If your MyOtherEpochDateField is not a time_t (AKA epoch) then you have to do even more work and you can no longer template your base search and have to pull all the events in and use a | eval MyOtherEpochDateField=strptime(MyOtherEpochDateField, "%some%time%format%here") | search MyOtherEpochDateField ....

0 Karma

niketn
Legend

@vivek_manoj, this can be done but will have performance impact on your dashboard/s. You should consider event timestamp to pick _time from reported_date during data ingestion if you want to build dashboard/s on reported_date.

Can you add some sample events with examples of reported_date? Also what is the field/value behind extraction of event timestamp (_time)?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...