<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Setting a time range from field data in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Setting-a-time-range-from-field-data/m-p/268095#M16946</link>
    <description>&lt;P&gt;I am trying to make 2 reports based on a time frame from field data. The first search has to pick the data from 1 week ago and the second search needs to get the data within 5 and 10 days from the initial timestamp in the field&lt;/P&gt;

&lt;P&gt;I achieved the first by using | where timeField&amp;gt;=relative_time(now(),"-1w") AND _time&amp;lt;=now()&lt;BR /&gt;
This correctly gives me data from this point until 1 week ago&lt;/P&gt;

&lt;P&gt;How do I alter the search to get data from within 5 and 10 days from the timestamp in timeField?&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jul 2016 11:47:10 GMT</pubDate>
    <dc:creator>Sverblaauw</dc:creator>
    <dc:date>2016-07-21T11:47:10Z</dc:date>
    <item>
      <title>Setting a time range from field data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Setting-a-time-range-from-field-data/m-p/268095#M16946</link>
      <description>&lt;P&gt;I am trying to make 2 reports based on a time frame from field data. The first search has to pick the data from 1 week ago and the second search needs to get the data within 5 and 10 days from the initial timestamp in the field&lt;/P&gt;

&lt;P&gt;I achieved the first by using | where timeField&amp;gt;=relative_time(now(),"-1w") AND _time&amp;lt;=now()&lt;BR /&gt;
This correctly gives me data from this point until 1 week ago&lt;/P&gt;

&lt;P&gt;How do I alter the search to get data from within 5 and 10 days from the timestamp in timeField?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2016 11:47:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Setting-a-time-range-from-field-data/m-p/268095#M16946</guid>
      <dc:creator>Sverblaauw</dc:creator>
      <dc:date>2016-07-21T11:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Setting a time range from field data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Setting-a-time-range-from-field-data/m-p/268096#M16947</link>
      <description>&lt;P&gt;Not sure I understand your requirement for the second search. Can you share some examples?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2016 17:29:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Setting-a-time-range-from-field-data/m-p/268096#M16947</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-07-21T17:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Setting a time range from field data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Setting-a-time-range-from-field-data/m-p/268097#M16948</link>
      <description>&lt;P&gt;I'm not sure I understand your intent, but I have a set of searches that adjust _time several different ways. Perhaps you can find what you are looking for in them.&lt;BR /&gt;
The set of searches looks back for the past 30 minutes for "DOT1X_State=unauthorized", dedups the results, uses stats to count up the results and rolls them into a report called "Last30". Then it looks back over the past 3 weeks and collects the data from the same 30 minute window of time into individual reports and manipulates _time for each of these reports so timechart will display them together.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=AAAAAAA earliest=-30m@m latest=-0m@m sourcetype=BBBBBBB DOT1X_State=unauthorized
 | timechart span=30s count as TOTAL
 | eval ReportKey="Last30"
 | append [search index=AAAAAAA sourcetype=BBBBBBB DOT1X_State=unauthorized earliest=-10110m@m latest=-10080m@m
 | timechart span=30s count as TOT
 | eval ReportKey="1WkAgo"
 | eval _time=_time+604800]
 | append [search index=AAAAAAA sourcetype=BBBBBBB DOT1X_State=unauthorized earliest=-20190m@m latest=-20160m@m
 | timechart span=30s count as TOT 
 | eval ReportKey="2WksAgo"
 | eval _time=_time+1209600]
 | append [search index=AAAAAAA sourcetype=BBBBBBB DOT1X_State=unauthorized earliest=-30270m@m latest=-30240m@m
 | timechart span=30s count as TOT 
 | eval ReportKey="3WksAgo"
 | eval _time=_time+1814400 ]
 | timechart avg(TOT) as Three_week_average values(TOTAL) as The_previous_30_minutes
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I hope you find a useful nugget in that.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:17:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Setting-a-time-range-from-field-data/m-p/268097#M16948</guid>
      <dc:creator>mydog8it</dc:creator>
      <dc:date>2020-09-29T10:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Setting a time range from field data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Setting-a-time-range-from-field-data/m-p/268098#M16949</link>
      <description>&lt;P&gt;Assuming you're talking about merging those two searches, give this a try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search [search your base search  | where timeField&amp;gt;=relative_time(now(),"-1w") AND _time&amp;lt;=now() | stats min(timeField) as timeField | eval earliest=relative_time(timeField,"-10d") | eval latest=relative_time(timeField,"-5d") | table earliest latest] | rest of the search
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 21 Jul 2016 20:02:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Setting-a-time-range-from-field-data/m-p/268098#M16949</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-07-21T20:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Setting a time range from field data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Setting-a-time-range-from-field-data/m-p/268099#M16950</link>
      <description>&lt;P&gt;Sorry for the lack of description in my question. This is not 100% what I wanted but I was able to use most of your search to create what I wanted&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2016 13:27:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Setting-a-time-range-from-field-data/m-p/268099#M16950</guid>
      <dc:creator>Sverblaauw</dc:creator>
      <dc:date>2016-07-22T13:27:32Z</dc:date>
    </item>
  </channel>
</rss>

