<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why does the date filtering only displays information from the first day of the week (Monday)? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346484#M102601</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have a little problem with the filtering date, I need a way to filter my dashboard so as to have the informations about the last week always starting on the first day of the week Monday even if we're wednesday, &lt;BR /&gt;
For example : &lt;BR /&gt;
If its Wednesday ; it's displays informations from the last Monday until Wednesay .&lt;/P&gt;

&lt;P&gt;Thank you for your help .&lt;/P&gt;</description>
    <pubDate>Mon, 12 Mar 2018 19:03:39 GMT</pubDate>
    <dc:creator>taha13</dc:creator>
    <dc:date>2018-03-12T19:03:39Z</dc:date>
    <item>
      <title>Why does the date filtering only displays information from the first day of the week (Monday)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346484#M102601</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have a little problem with the filtering date, I need a way to filter my dashboard so as to have the informations about the last week always starting on the first day of the week Monday even if we're wednesday, &lt;BR /&gt;
For example : &lt;BR /&gt;
If its Wednesday ; it's displays informations from the last Monday until Wednesay .&lt;/P&gt;

&lt;P&gt;Thank you for your help .&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 19:03:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346484#M102601</guid>
      <dc:creator>taha13</dc:creator>
      <dc:date>2018-03-12T19:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the date filtering only displays information from the first day of the week (Monday)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346485#M102602</link>
      <description>&lt;P&gt;Whats the time range you're using?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 19:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346485#M102602</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-03-12T19:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the date filtering only displays information from the first day of the week (Monday)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346486#M102603</link>
      <description>&lt;P&gt;i don't really know, i just start using splunk&lt;BR /&gt;
For the last week, i have earliest_time:-1w@w latest_time:-0d@d&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:25:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346486#M102603</guid>
      <dc:creator>taha13</dc:creator>
      <dc:date>2020-09-29T18:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the date filtering only displays information from the first day of the week (Monday)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346487#M102604</link>
      <description>&lt;P&gt;@taha13, can you check the following answer on similar lines?&lt;A href="https://answers.splunk.com/answers/527234/making-same-query-run-for-different-times.html"&gt;https://answers.splunk.com/answers/527234/making-same-query-run-for-different-times.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 19:49:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346487#M102604</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-03-12T19:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the date filtering only displays information from the first day of the week (Monday)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346488#M102605</link>
      <description>&lt;P&gt;@niketnilay thank you for your answer,i chacked the answer ,but since i am new to develop on splunk, i do not really see the relation between my problem and this one&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 08:49:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346488#M102605</guid>
      <dc:creator>taha13</dc:creator>
      <dc:date>2018-03-13T08:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the date filtering only displays information from the first day of the week (Monday)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346489#M102606</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;
You can try using &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;earliest=-1w
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;for exactly seven days. So if you check on Wednesday 12 p.m. it will show you from the previous wednesday 12 p.m.&lt;/P&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;earliest=-1w@d
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For the entire day. So if you check on Wednesday - irrespective of the time, it will show you the results of the whole day.&lt;/P&gt;

&lt;P&gt;Here's the documentation, for you to understand this better&lt;BR /&gt;
&lt;CODE&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/SearchTimeModifiers" target="test_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/SearchTimeModifiers&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 09:54:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346489#M102606</guid>
      <dc:creator>bangalorep</dc:creator>
      <dc:date>2018-03-13T09:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the date filtering only displays information from the first day of the week (Monday)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346490#M102607</link>
      <description>&lt;P&gt;@taha13, you must first read and understand Time Modifiers and Snap To syntax from Splunk Documentation: &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Search/Specifytimemodifiersinyoursearch"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Search/Specifytimemodifiersinyoursearch&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Please try the following run anywhere dashboard. Based on the current week day it sets the following two time ranges:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;If current Week Day is &lt;CODE&gt;Mon, Tue or&lt;BR /&gt;
Wed&lt;/CODE&gt;, it sets the earliest time as&lt;BR /&gt;
&lt;CODE&gt;-1w@w1&lt;/CODE&gt; or &lt;CODE&gt;Previous Week @ Monday&lt;/CODE&gt;&lt;BR /&gt;
and latest time as &lt;CODE&gt;-0w@w&lt;/CODE&gt; or &lt;CODE&gt;Current&lt;BR /&gt;
Week @ Sunday&lt;/CODE&gt;.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Else if the current Week Day is &lt;CODE&gt;Thu,&lt;BR /&gt;
Fri, Sat or Sun&lt;/CODE&gt;, it sets the&lt;BR /&gt;
earliest time as &lt;CODE&gt;-1w@w1&lt;/CODE&gt; or&lt;BR /&gt;
&lt;CODE&gt;Previous Week @ Monday&lt;/CODE&gt; and latest&lt;BR /&gt;
time as &lt;CODE&gt;-0w@w3&lt;/CODE&gt; or &lt;CODE&gt;Current Week @&lt;BR /&gt;
Wednesday&lt;/CODE&gt;.&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In order to test various weekdays, replace the following search pipe &lt;CODE&gt;| eval WeekDay=strftime(_time,"%a")&lt;/CODE&gt; with your specific weekday for example &lt;CODE&gt;| eval WeekDay ="Wed"&lt;/CODE&gt; or &lt;CODE&gt;| eval WeekDay ="Thu"&lt;/CODE&gt; etc.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;Earliest and Latest Time based on current day&amp;lt;/label&amp;gt;
  &amp;lt;search&amp;gt;
    &amp;lt;query&amp;gt;
       | makeresults
       | eval WeekDay=strftime(_time,"%a")
       | eval Hour=strftime(_time,"%H")
       | eval Time=case(WeekDay in ("Mon","Tue","Wed"),"earliest=-1w@w1 latest=-0w@w",true(),"earliest=-1w@w1 latest=-0w@w3") 
       | table _time WeekDay Hour Time
     &amp;lt;/query&amp;gt;
    &amp;lt;progress&amp;gt;
      &amp;lt;set token="queryTimeRange"&amp;gt;$result.Time$&amp;lt;/set&amp;gt;
      &amp;lt;set token="tokWeekDay"&amp;gt;$result.WeekDay$&amp;lt;/set&amp;gt;
    &amp;lt;/progress&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;&amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;title&amp;gt;Today's Week Day: $tokWeekDay$ - Time Range: $queryTimeRange$&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal sourcetype=splunkd log_level="ERROR" $queryTimeRange$
   | stats count as Errors
   | addinfo
   | fieldformat info_min_time=strftime(info_min_time,"%c")
   | fieldformat info_max_time=strftime(info_max_time,"%c")
   | fieldformat info_search_time=strftime(info_search_time,"%c")
   | table Errors info_min_time info_max_time info_search_time
         &amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Please try out and confirm.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 10:43:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346490#M102607</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-03-13T10:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the date filtering only displays information from the first day of the week (Monday)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346491#M102608</link>
      <description>&lt;P&gt;Tnak you for your answer @niketnilay&lt;/P&gt;

&lt;P&gt;But,can you just tell me where should i put this query in my code&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &amp;lt;condition label="Semaine précédente"&amp;gt;
          &amp;lt;set token="earliest1_token"&amp;gt;$value$&amp;lt;/set&amp;gt;
          &amp;lt;set token="earliest_token"&amp;gt;$value$&amp;lt;/set&amp;gt;
          &amp;lt;set token="latest_token"&amp;gt;-0w@w&amp;lt;/set&amp;gt;
          &amp;lt;set token="time_token"&amp;gt;true&amp;lt;/set&amp;gt;

---------------------

&amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;title&amp;gt;Nombre de clients éligibles au Tchat&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;|loadjob savedsearch=":ied:$loadjob_token_job$"
            |search $media_token$ $chatOrigin_token$

            |eval date_time = strftime(_time,"%Y-%m-%d") 
              | eval earliest_time_relative=relative_time(now(),"$earliest_token$")
                | eval earliest_time = strftime(earliest_time_relative,"%Y-%m-%d")

                | eval earliest1_time_relative=relative_time(now(),"$earliest1_token$")
                | eval earliest1_time = strftime(earliest1_time_relative,"%Y-%m-%d")

                | eval latest_time_relative=relative_time(now(),"$latest_token$")
                | eval latest_time = strftime(latest_time_relative,"%Y-%m-%d")

                | eval date = strftime(_time,"%Y-%m-%d")
                | where date == "$time_token$" OR (date_time &amp;amp;gt;= earliest1_time AND latest_time &amp;amp;gt;= date_time) OR date_time&amp;amp;gt;= earliest_time

              |stats dc(eval(if((isEligible_lo=1), client, NULL))) AS Nombre_clients_éligibles_au_Tchat BY _time,media,chatOrigin
                | stats SUM(Nombre_clients_éligibles_au_Tchat) AS snb
        | fields snb&amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="useThousandSeparators"&amp;gt;0&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
&amp;lt;row&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 13 Mar 2018 12:35:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346491#M102608</guid>
      <dc:creator>taha13</dc:creator>
      <dc:date>2018-03-13T12:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the date filtering only displays information from the first day of the week (Monday)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346492#M102609</link>
      <description>&lt;P&gt;my question is : if i check n wednesday,it will show me the result from monday of the last week&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 12:37:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346492#M102609</guid>
      <dc:creator>taha13</dc:creator>
      <dc:date>2018-03-13T12:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the date filtering only displays information from the first day of the week (Monday)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346493#M102610</link>
      <description>&lt;P&gt;Before I can assist further, have you tested above Run Anywhere dashboard of mine? Does it set the earliest and latest time as per expectations? And have you understood how that dashboard is working?&lt;/P&gt;

&lt;P&gt;Following run anywhere search can be the first line of your dashboard, may be after &lt;CODE&gt;&amp;lt;label&amp;gt;&lt;/CODE&gt; and &lt;CODE&gt;&amp;lt;description&amp;gt;&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &amp;lt;query&amp;gt;
    | makeresults
    | eval WeekDay=strftime(_time,"%a")
    | eval Hour=strftime(_time,"%H")
    | eval Time=case(WeekDay in ("Mon","Tue","Wed"),"earliest=-1w@w1 latest=-0w@w",true(),"earliest=-1w@w1 latest=-0w@w3") 
    | table _time WeekDay Hour Time
  &amp;lt;/query&amp;gt;
 &amp;lt;progress&amp;gt;
   &amp;lt;set token="queryTimeRange"&amp;gt;$result.Time$&amp;lt;/set&amp;gt;
 &amp;lt;/progress&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then use &lt;CODE&gt;$queryTimeRange$&lt;/CODE&gt; in your base search for the queries that should pick up the earliest and latest time as per your question. &lt;/P&gt;

&lt;P&gt;In your dashboard example seems like you are loading the result of a saved search, which might have already run. Maybe you can have two saved searches instead and set the token for their saved search names instead.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 10:54:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346493#M102610</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-03-14T10:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the date filtering only displays information from the first day of the week (Monday)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346494#M102611</link>
      <description>&lt;P&gt;@taha13, is your issue resolved? Please accept the answer if it is to mark this question as answered!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Apr 2018 12:55:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-date-filtering-only-displays-information-from-the/m-p/346494#M102611</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-04-04T12:55:08Z</dc:date>
    </item>
  </channel>
</rss>

