Hi all,
I have a panel in a dashboard that loads a simple count of a certain search (number of unique hosts in a series of .json files), and the whole dashboard is controlled by a central time picker. I'd like to be able to show how the trend of number of hosts reported has changed if I change the value in the time picker.
EG: If I choose last 24 hours, it shows the single value as the last 24 hours, but should also have a trend of the previous 24 hours. If I then change that to 7 days, the single value will update and the trend will be the previous 7 days.
I've tried several attempts based on other questions posted and their answers as well as third party blogs, but have found nothing concrete. Also, reflecting items in the Sample Dashboards app hasn't led me anywhere.
Latest version of Splunk, btw.
... View more