Hi, I initialize a token with a value (number in hex) and use this token in search. However, the dashboard still asks for input? My XML is below. Please advise. Thanks in advance.
Query Details by Day Clone
Distribution of count and response by host per day
<set token="InQueryHash">b6ffee0d1c4f18ba</set>
<panel>
<table>
<title>Query latency per host per hour</title>
<search>
<query>(splunk_server_group=default OR splunk_server_group=distapps) (index=distapps)
sourcetype="aa:bb" organizationId="cc" pname=dd.214 Request action=query
runTime>0 (respCode=200 OR respCode=408)
queryHash=$InQueryHash$
| bucket _time span=1h
| eval Date=strftime(_time,"%m/%d/%y %H:%M:%S")
| stats count(host) as querycount
avg(runTime) as avgtime
min(runTime) as mintime
max(runTime) as maxtime
perc95(runTime) as perc95time
perc50(runTime) as medtime
stdev(runTime) as stddevtime
by host, _time</query>
<earliest>1529798400</earliest>
<latest>1530403199</latest>
</search>
</table>
</panel>
... View more