<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Timerange as an argument in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Timerange-as-an-argument/m-p/579224#M102260</link>
    <description>&lt;P&gt;I am working on using the same time range as an argument used in the Time range picker.&amp;nbsp; how do I do that?&lt;BR /&gt;&lt;BR /&gt;|metadata index=* type=hosts|eval First_Time=strftime(firstTime, "%Y-%d-%m %H:%M")&lt;BR /&gt;&lt;BR /&gt;This is my search query and I need the "firstTime" values to be the same value as used in the search head (i.e) if this search is run from 1st Nov to 30th Nov, I need the firstTime values also in this specified time range as given in the time-range picker.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Dec 2021 07:37:06 GMT</pubDate>
    <dc:creator>Raghul_S</dc:creator>
    <dc:date>2021-12-24T07:37:06Z</dc:date>
    <item>
      <title>Timerange as an argument</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timerange-as-an-argument/m-p/579224#M102260</link>
      <description>&lt;P&gt;I am working on using the same time range as an argument used in the Time range picker.&amp;nbsp; how do I do that?&lt;BR /&gt;&lt;BR /&gt;|metadata index=* type=hosts|eval First_Time=strftime(firstTime, "%Y-%d-%m %H:%M")&lt;BR /&gt;&lt;BR /&gt;This is my search query and I need the "firstTime" values to be the same value as used in the search head (i.e) if this search is run from 1st Nov to 30th Nov, I need the firstTime values also in this specified time range as given in the time-range picker.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Dec 2021 07:37:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timerange-as-an-argument/m-p/579224#M102260</guid>
      <dc:creator>Raghul_S</dc:creator>
      <dc:date>2021-12-24T07:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Timerange as an argument</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timerange-as-an-argument/m-p/579227#M102261</link>
      <description>&lt;P&gt;It ain't that easy. In fact it might not be possible at all.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.2.2111/SearchReference/Metadata#Time_ranges" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.2.2111/SearchReference/Metadata#Time_ranges&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Dec 2021 08:17:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timerange-as-an-argument/m-p/579227#M102261</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-12-24T08:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Timerange as an argument</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Timerange-as-an-argument/m-p/579228#M102262</link>
      <description>&lt;P&gt;Hii,&amp;nbsp;&lt;BR /&gt;Thanks for responding, actually Implemented it in a different way using 2 queries!!&lt;BR /&gt;thanks anyway!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Dec 2021 08:25:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Timerange-as-an-argument/m-p/579228#M102262</guid>
      <dc:creator>Raghul_S</dc:creator>
      <dc:date>2021-12-24T08:25:43Z</dc:date>
    </item>
  </channel>
</rss>

