Splunk Dashboard Time Picker
Aug 25, 2017 · 1 min read
Edit Dashboard using Period to search must be setup token into panel by Dashboard source XML
Create new item “Time”
Token of time is “time_tok1”
In searchString TAG
<searchString>
<earliestTime>$time_tok1.earliest$</earliestTime>
<latestTime>$time_tok1.latest$</latestTime>
</searchString>OR
In search TAG
<search>
<earliest>$time_tok1.earliest$</earliest>
<latest>$time_tok1.latest$</latest>
</search>