Hi,
How to show the last indexed file's date in the panel title or label in splunk dashboard.
the input lookup file i am using in my queries looks like abc_ddmmyyyy.csv
I am doing some calculations on this lookup file and populating the dashboard panel.
Now i want to somehow show the date from the filename which should get dynamically populated .
Thanks
You can use the solution from below post (basically adding a <search>
element which will run a search and set timelabel
token which will be used in the dashboard label.
https://answers.splunk.com/answers/590196/dashboard-title-display-date-as-ddmmyyyy.html
Your search element can be this
<search>
<query>|tstats latest(source) as source WHERE index=yourIndex sourcetype=yourSourcetype | eval source=replace(source,".+_(\d{8}\.csv","\1") </query>
<earliest>$field1.earliest$</earliest>
<latest>$field1.latest$</latest>
<progress>
<eval token="timelabel">$result.source$</eval>
</progress>
</search>
You can use the solution from below post (basically adding a <search>
element which will run a search and set timelabel
token which will be used in the dashboard label.
https://answers.splunk.com/answers/590196/dashboard-title-display-date-as-ddmmyyyy.html
Your search element can be this
<search>
<query>|tstats latest(source) as source WHERE index=yourIndex sourcetype=yourSourcetype | eval source=replace(source,".+_(\d{8}\.csv","\1") </query>
<earliest>$field1.earliest$</earliest>
<latest>$field1.latest$</latest>
<progress>
<eval token="timelabel">$result.source$</eval>
</progress>
</search>
Instead of eval token when i changed that line to set token it worked.
$result.source$
thanks @Somesoni2
Hi @somesoni2
I tried implementinig this but the token is not giving me the desired result.
Also could you please tell me whats the significance of field1.earliest whats field1 here ?
Ohh.. I picked the code from the post and tried to update it to fit your requirement, but missed updating that. That will be either your dashboard's time range picker OR you can specify a custom explicit time range.
@surekhasplunk are you uploading the csv file as a lookup file or indexing the csv file?
Hi @niketnilay,
Yes am indexing the files.