<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Confused on Time modifiers in Searches in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Confused-on-Time-modifiers-in-Searches/m-p/463448#M130648</link>
    <description>&lt;P&gt;That's what I understood and is not expected behavior.  Please open a support case.&lt;/P&gt;</description>
    <pubDate>Thu, 28 May 2020 20:13:27 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-05-28T20:13:27Z</dc:date>
    <item>
      <title>Confused on Time modifiers in Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Confused-on-Time-modifiers-in-Searches/m-p/463445#M130645</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I must be missing something. I have a simple search using a time modifier: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=MyIndex earliest=-30m 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;My expectation is when I search, the results will be searched and returned only over the last 30 minutes of events. When I use the time picker and set to ALL TIME, it still only returns the last 30 minutes but searches over ALL EVENTS?  Is this the correct behavior? &lt;/P&gt;

&lt;P&gt;I looked at the job log and it did have the earliest event as the first event in the index (ALL TIME) with the time modifier. Read this a few times, &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Search/Specifytimemodifiersinyoursearch"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Search/Specifytimemodifiersinyoursearch&lt;/A&gt; and didn't see any verbiage to this behavior.&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;

&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 17:05:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Confused-on-Time-modifiers-in-Searches/m-p/463445#M130645</guid>
      <dc:creator>chrisboy68</dc:creator>
      <dc:date>2020-05-28T17:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Confused on Time modifiers in Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Confused-on-Time-modifiers-in-Searches/m-p/463446#M130646</link>
      <description>&lt;P&gt;The verbiage you seek is there at that link.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;A time range that you specify in the Search bar, or in a saved search, overrides the time range that is selected in the Time Range Picker.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you specify &lt;CODE&gt;earliest=-30m&lt;/CODE&gt; in your query then the time picker should be ignored.  If that's not the case then you may have found a bug and should open a support case.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 17:18:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Confused-on-Time-modifiers-in-Searches/m-p/463446#M130646</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-28T17:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Confused on Time modifiers in Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Confused-on-Time-modifiers-in-Searches/m-p/463447#M130647</link>
      <description>&lt;P&gt;Maybe I'm not explaining it correctly. The events being returned are always within the time modifier on the search. &lt;/P&gt;

&lt;P&gt;Try this(for those watching): index=main earliest=-30m for last 4 hours and look at the job inspector for earliestTime, then do the same for ALL Time. The earliestTime is the first event of the index, which tells me splunk is searching all the events and not limiting to a 30 min window based on _time. It takes much longer too, I usually kill it.&lt;/P&gt;

&lt;P&gt;Tx&lt;/P&gt;

&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 19:01:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Confused-on-Time-modifiers-in-Searches/m-p/463447#M130647</guid>
      <dc:creator>chrisboy68</dc:creator>
      <dc:date>2020-05-28T19:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Confused on Time modifiers in Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Confused-on-Time-modifiers-in-Searches/m-p/463448#M130648</link>
      <description>&lt;P&gt;That's what I understood and is not expected behavior.  Please open a support case.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 20:13:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Confused-on-Time-modifiers-in-Searches/m-p/463448#M130648</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-28T20:13:27Z</dc:date>
    </item>
  </channel>
</rss>

