I have a dashboard similar to this one:
Instead of the hard-coded value "123" in the search "Timechart with baseline overlay" i want to use the "rate" field which is calculated in the "statsBase" search. I could not find anything suitable in the documentation. Is this even possible?
As I workaround I tried to use the `loadjob` command to access the result of the second base search as shown in the code below:
When I open the panel in search using the magnifier icon, the generated search works perfectly however.
I'm on Splunk enterprise 6.3.1 by the way.
↧