<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: earliest/latest returning zero results in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/earliest-latest-returning-zero-results/m-p/341925#M101319</link>
    <description>&lt;P&gt;try this&lt;/P&gt;

&lt;P&gt;index=firewall earliest=-24h@h latest=-12h@h&lt;/P&gt;

&lt;P&gt;please go through below link,&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/Search/Specifytimemodifiersinyoursearch"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.2/Search/Specifytimemodifiersinyoursearch&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Aug 2017 17:49:36 GMT</pubDate>
    <dc:creator>sbbadri</dc:creator>
    <dc:date>2017-08-02T17:49:36Z</dc:date>
    <item>
      <title>earliest/latest returning zero results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/earliest-latest-returning-zero-results/m-p/341924#M101318</link>
      <description>&lt;P&gt;I apologize as I feel I am missing something very basic, but for the life of me I cannot get this query to work.  I have a simple query and it is returning zero results.  If I remove the earliest/latest, I get tons of results.&lt;/P&gt;

&lt;P&gt;What syntactical mistake am I making?  I have the time picker set to 1 hour, but my understanding is that when using earliest/latest, they override the time picker.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=firewall earliest=-24@h latest=-12@h
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 02 Aug 2017 17:47:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/earliest-latest-returning-zero-results/m-p/341924#M101318</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2017-08-02T17:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: earliest/latest returning zero results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/earliest-latest-returning-zero-results/m-p/341925#M101319</link>
      <description>&lt;P&gt;try this&lt;/P&gt;

&lt;P&gt;index=firewall earliest=-24h@h latest=-12h@h&lt;/P&gt;

&lt;P&gt;please go through below link,&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/Search/Specifytimemodifiersinyoursearch"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.2/Search/Specifytimemodifiersinyoursearch&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 17:49:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/earliest-latest-returning-zero-results/m-p/341925#M101319</guid>
      <dc:creator>sbbadri</dc:creator>
      <dc:date>2017-08-02T17:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: earliest/latest returning zero results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/earliest-latest-returning-zero-results/m-p/341926#M101320</link>
      <description>&lt;P&gt;I believe you are correct, and the explanation is that -24 means "subtract 24 seconds".  &lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 17:52:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/earliest-latest-returning-zero-results/m-p/341926#M101320</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-08-02T17:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: earliest/latest returning zero results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/earliest-latest-returning-zero-results/m-p/341927#M101321</link>
      <description>&lt;P&gt;Ahhh... I completely overlooked that extra character.  I read the documentation but was clearly scanning the syntax too fast.  Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 17:58:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/earliest-latest-returning-zero-results/m-p/341927#M101321</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2017-08-02T17:58:28Z</dc:date>
    </item>
  </channel>
</rss>

