<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to enable Splunk IT Service Intelligence to use earliest=@d modifier to execute search at midnight? in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/How-to-enable-Splunk-IT-Service-Intelligence-to-use-earliest-d/m-p/203753#M20</link>
    <description>&lt;P&gt;Are you sure the data is the same? Also, "earliest" and "latest" in a KPI Base Search is not recommended. We recommend that you use the KPI Interval option in the UI if you can.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Nov 2016 21:06:28 GMT</pubDate>
    <dc:creator>rossl_splunk</dc:creator>
    <dc:date>2016-11-03T21:06:28Z</dc:date>
    <item>
      <title>How to enable Splunk IT Service Intelligence to use earliest=@d modifier to execute search at midnight?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/How-to-enable-Splunk-IT-Service-Intelligence-to-use-earliest-d/m-p/203750#M17</link>
      <description>&lt;P&gt;When you write &lt;CODE&gt;earliest=@d&lt;/CODE&gt;, it executes search from midnight in Splunk Cloud. But in Splunk IT Service Intelligence (ITSI), it executes from the last 24 hours. My preference is for ITSI to perform as it does in Splunk Cloud. So is this an issue in Splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 22:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/How-to-enable-Splunk-IT-Service-Intelligence-to-use-earliest-d/m-p/203750#M17</guid>
      <dc:creator>anveshdodda</dc:creator>
      <dc:date>2016-11-02T22:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable Splunk IT Service Intelligence to use earliest=@d modifier to execute search at midnight?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/How-to-enable-Splunk-IT-Service-Intelligence-to-use-earliest-d/m-p/203751#M18</link>
      <description>&lt;P&gt;Where are you defining that search? Is that in a KPI search? Also are you using a different version of ITSI than is installed on the cloud instance?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 01:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/How-to-enable-Splunk-IT-Service-Intelligence-to-use-earliest-d/m-p/203751#M18</guid>
      <dc:creator>rossl_splunk</dc:creator>
      <dc:date>2016-11-03T01:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable Splunk IT Service Intelligence to use earliest=@d modifier to execute search at midnight?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/How-to-enable-Splunk-IT-Service-Intelligence-to-use-earliest-d/m-p/203752#M19</link>
      <description>&lt;P&gt;Hi ..&lt;BR /&gt;
Thanks for your reply &lt;/P&gt;

&lt;P&gt;Yes it's in the kpi base search ...&lt;BR /&gt;
I use the same one that is installed on the cloud instance ....&lt;BR /&gt;
Also when i put kpi summary as off then I get the same count as I get in base core splunk but when I change the kpi summary to on that's where I get the kpi count different ...&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 02:15:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/How-to-enable-Splunk-IT-Service-Intelligence-to-use-earliest-d/m-p/203752#M19</guid>
      <dc:creator>anveshdodda</dc:creator>
      <dc:date>2016-11-03T02:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable Splunk IT Service Intelligence to use earliest=@d modifier to execute search at midnight?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/How-to-enable-Splunk-IT-Service-Intelligence-to-use-earliest-d/m-p/203753#M20</link>
      <description>&lt;P&gt;Are you sure the data is the same? Also, "earliest" and "latest" in a KPI Base Search is not recommended. We recommend that you use the KPI Interval option in the UI if you can.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 21:06:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/How-to-enable-Splunk-IT-Service-Intelligence-to-use-earliest-d/m-p/203753#M20</guid>
      <dc:creator>rossl_splunk</dc:creator>
      <dc:date>2016-11-03T21:06:28Z</dc:date>
    </item>
  </channel>
</rss>

