How to Add Time Input option to Splunk Dashboard

How to Add Time Input option to Splunk Dashboard

The main purpose of adding inputs in Splunk dashboard is to make dashboards dynamic. There are few easy steps to add time input option to Splunk dashboard.

Step 1:

Open a dashboard which you want to make dynamic. You can see the Edit option on top right corner of the dashboard. Click on the Edit option.

time1

Step 2:

After clicking Edit option you can see Add Input option in the dashboard , click on that. Then click on Time.

time2

Step 3:

Now edit the Time option . There you have to give a Label, which will be shown  on the dashboard.  Then click the check box beside Search on Change . If you don’t click this then it will not effect the dashboard. So every time you have to click the check box. Give a Token name by which value will pass. Here we have a given a token name as time_token. We have selected the default value as Last 24 hours . At last click on Apply button.

time3

Step 4:

You have to pass the token inside the panels which you want to make dependent upon the token. Click on Edit Search of that panel. Select the Time Range as Shared Time Picker(token_name) . Click on Apply button.

time4

Step 5:

After making changes in the dashboard click on Save button to save all the changes and refresh the dashboard tab once.

time5

Step 6:

Finally Time Input option is added in the dashboard. You can select the time as per the requirement . In the panel results will come depending upon the time you selected . Here we have given the time range as Last 4 hours so in the panel we are getting data of last 4 hours.

time6

Hope this has helped you in achieving the below requirement without fail:

How to Add Time Input option to Splunk Dashboard

 

Happy Splunking !!

Advertisements

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.