<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Specify specific time range in query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516071#M144949</link>
    <description>&lt;P&gt;Hello Splunkers&lt;/P&gt;&lt;P&gt;I have an IIS log&amp;nbsp; that I am testing against and I have a need to test for a specified range&lt;/P&gt;&lt;P&gt;The _time field in the log is formatted like this&amp;nbsp; &amp;nbsp;2020-08-23T21:25:33.437-0400&lt;/P&gt;&lt;P&gt;2020-08-23T21:25:33.437-0400&lt;/P&gt;&lt;P&gt;I want to query everything between&amp;nbsp;&amp;nbsp;21:25:33 and&amp;nbsp;21:25:43&lt;/P&gt;&lt;P&gt;2020-08-23T21:25:33.437-0400&lt;BR /&gt;2020-08-23T21:25:34.133-0400&lt;BR /&gt;2020-08-23T21:25:35.267-0400&lt;BR /&gt;2020-08-23T21.25:36:42.683-0400&lt;BR /&gt;2020-08-23T21:25:37.270-0400&lt;BR /&gt;2020-08-23T21:25:38.013-0400&lt;BR /&gt;2020-08-23T21:25:39.320-0400&lt;BR /&gt;2020-08-23T21:25:40.753-0400&lt;BR /&gt;2020-08-23T21:25:41.597-0400&lt;BR /&gt;2020-08-23T21:25:42.013-0400&lt;BR /&gt;2020-08-23T21:25:43.353-0400&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my search would look something like this.&amp;nbsp; What is the best way to do this?&lt;/P&gt;&lt;P&gt;| where _time &amp;lt; blah _time &amp;gt;= blah&lt;/P&gt;</description>
    <pubDate>Tue, 25 Aug 2020 16:02:30 GMT</pubDate>
    <dc:creator>irishmanjb</dc:creator>
    <dc:date>2020-08-25T16:02:30Z</dc:date>
    <item>
      <title>Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516071#M144949</link>
      <description>&lt;P&gt;Hello Splunkers&lt;/P&gt;&lt;P&gt;I have an IIS log&amp;nbsp; that I am testing against and I have a need to test for a specified range&lt;/P&gt;&lt;P&gt;The _time field in the log is formatted like this&amp;nbsp; &amp;nbsp;2020-08-23T21:25:33.437-0400&lt;/P&gt;&lt;P&gt;2020-08-23T21:25:33.437-0400&lt;/P&gt;&lt;P&gt;I want to query everything between&amp;nbsp;&amp;nbsp;21:25:33 and&amp;nbsp;21:25:43&lt;/P&gt;&lt;P&gt;2020-08-23T21:25:33.437-0400&lt;BR /&gt;2020-08-23T21:25:34.133-0400&lt;BR /&gt;2020-08-23T21:25:35.267-0400&lt;BR /&gt;2020-08-23T21.25:36:42.683-0400&lt;BR /&gt;2020-08-23T21:25:37.270-0400&lt;BR /&gt;2020-08-23T21:25:38.013-0400&lt;BR /&gt;2020-08-23T21:25:39.320-0400&lt;BR /&gt;2020-08-23T21:25:40.753-0400&lt;BR /&gt;2020-08-23T21:25:41.597-0400&lt;BR /&gt;2020-08-23T21:25:42.013-0400&lt;BR /&gt;2020-08-23T21:25:43.353-0400&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my search would look something like this.&amp;nbsp; What is the best way to do this?&lt;/P&gt;&lt;P&gt;| where _time &amp;lt; blah _time &amp;gt;= blah&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:02:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516071#M144949</guid>
      <dc:creator>irishmanjb</dc:creator>
      <dc:date>2020-08-25T16:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516073#M144950</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;the easiest way is to use earliest and latest on your query like&lt;/P&gt;&lt;LI-CODE lang="java"&gt;index=&amp;lt;your index&amp;gt; earliest="08/23/2020:21:25:33" latest="08/33/2020:21:25:43"&lt;/LI-CODE&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:17:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516073#M144950</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-25T16:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516075#M144952</link>
      <description>&lt;P&gt;thanks will test after lunch&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 16:18:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516075#M144952</guid>
      <dc:creator>irishmanjb</dc:creator>
      <dc:date>2020-08-25T16:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516090#M144957</link>
      <description>&lt;P&gt;Here is my query&lt;/P&gt;&lt;P&gt;I have a CSV lookup file that I am trying to test against because I don't have enough production data&lt;/P&gt;&lt;P&gt;| inputlookup myfile.csv&lt;BR /&gt;| search InfoSourceID="2" OR InfoSourceID="3" ErrorCode=*&lt;BR /&gt;| where _time &amp;lt; TIME_RANGE_START AND _time &amp;gt;= TIME_RANGE_END&lt;BR /&gt;| streamstats reset_after=(isnull(ErrorCode)) count&lt;BR /&gt;|Stats latest(eval(if(count&amp;gt;=10,_time,NULL))) as _time&lt;BR /&gt;&lt;BR /&gt;I am reading through this file to test the triggering of an alert when 10 consecutive errors are found in the lookup file.&amp;nbsp; What would be the correct syntax for this line?&amp;nbsp;|&lt;STRONG&gt; where _time &amp;lt; TIME_RANGE_START AND _time &amp;gt;= TIME_RANGE_END&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 17:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516090#M144957</guid>
      <dc:creator>irishmanjb</dc:creator>
      <dc:date>2020-08-25T17:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516093#M144959</link>
      <description>&lt;P&gt;the ten errors in my log I want to trigger my alert on are&amp;nbsp;&lt;/P&gt;&lt;P&gt;2020-08-23T21:25:33.437-0400&lt;BR /&gt;2020-08-23T21:25:34.133-0400&lt;BR /&gt;2020-08-23T21:25:35.267-0400&lt;BR /&gt;2020-08-23T21.25:36:42.683-0400&lt;BR /&gt;2020-08-23T21:25:37.270-0400&lt;BR /&gt;2020-08-23T21:25:38.013-0400&lt;BR /&gt;2020-08-23T21:25:39.320-0400&lt;BR /&gt;2020-08-23T21:25:40.753-0400&lt;BR /&gt;2020-08-23T21:25:41.597-0400&lt;BR /&gt;2020-08-23T21:25:42.013-0400&lt;BR /&gt;2020-08-23T21:25:43.353-0400&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 17:42:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516093#M144959</guid>
      <dc:creator>irishmanjb</dc:creator>
      <dc:date>2020-08-25T17:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516108#M144972</link>
      <description>&lt;P&gt;Can you share one sample value of _time from your lookup file?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 18:20:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516108#M144972</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-25T18:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516110#M144973</link>
      <description>&lt;P&gt;sure here is the first record&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;_time&lt;/P&gt;&lt;P&gt;2020-08-23T21:25:33.437-0400&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 18:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516110#M144973</guid>
      <dc:creator>irishmanjb</dc:creator>
      <dc:date>2020-08-25T18:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516117#M144976</link>
      <description>&lt;P&gt;Is it showing same format when you do |inputlookup yourlookupname | rename _time as testingtime&lt;/P&gt;&lt;P&gt;can you let me know how is the format of testingtime field value.share one sample value of testingtime.&lt;/P&gt;&lt;P&gt;I am trying to understand _time is recognized by Splunk or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 18:35:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516117#M144976</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-25T18:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516129#M144978</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what I am tinkering with now but its still not working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;My file the top 10 results all have a data in the errorcode field and are all InfoSourceID 3&lt;/P&gt;&lt;P&gt;| inputlookup mylookupfile.csv&lt;BR /&gt;| search InfoSourceID="2" OR InfoSourceID="3" ErrorCode=*&lt;BR /&gt;| eval hourmin = strftime(_time, "%H%M")&lt;BR /&gt;| where (hourmin &amp;gt;= 2124 AND hourmin &amp;lt;= 2126)&lt;BR /&gt;| streamstats reset_after=(isnull(ErrorCode)) count&lt;BR /&gt;|stats latest(eval(if(count&amp;gt;=10,_time,NULL))) as _time&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 19:05:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516129#M144978</guid>
      <dc:creator>irishmanjb</dc:creator>
      <dc:date>2020-08-25T19:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516131#M144980</link>
      <description>&lt;P&gt;when I rename _time testingtime this is what I see&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2020-08-23T21:25:33.437-0400&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 19:13:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516131#M144980</guid>
      <dc:creator>irishmanjb</dc:creator>
      <dc:date>2020-08-25T19:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516144#M145012</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;here is concept how this can do if you are using lookup file instead of reading those from index. If/when you are looking those directly from index please use my first answer!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="java"&gt;index=_internal 
| head 1
| eval _raw="Time,InfoSourceID,ErrorCode
2020-08-23T21:25:33.437-0400,2,2
2020-08-23T21:25:34.133-0400,2,2
2020-08-23T21:25:35.267-0400,3,3
2020-08-23T21:25:36.683-0400,2,3
2020-08-23T21:25:37.270-0400,3,3
2020-08-23T21:25:38.013-0400,3,2
2020-08-23T21:25:39.320-0400,1,3
2020-08-23T21:25:40.753-0400,1,2
2020-08-23T21:25:41.597-0400,2,2
2020-08-23T21:25:42.013-0400,2,3
2020-08-23T21:25:43.353-0400,3,3"
| multikv forceheader=1
| eval TIME_RANGE_START="08/23/2020:21:25:33-0400", TIME_RANGE_END="08/23/2020:21:25:43-0400"
| eval time = strptime(Time, "%FT%T.%3Q%z"), TIME_RANGE_START=strptime(TIME_RANGE_START, "%m/%d/%Y:%T%z"), TIME_RANGE_END=strptime(TIME_RANGE_END, "%m/%d/%Y:%T%z")
| rename COMMENT AS "Previous was setting up sample data and valuse. Those don't need when reading from index. Also remove above | when ... and use first answer to get data"
| table time,TIME_RANGE_START,TIME_RANGE_END, InfoSourceID, ErrorCode| search InfoSourceID="2" OR InfoSourceID="3" ErrorCode=*
| where (time &amp;gt;= TIME_RANGE_START) AND (time &amp;lt;= TIME_RANGE_END)
| streamstats reset_after=(isnull(ErrorCode)) count&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next time it helps to get correct answer if/when you tell all relevant items&amp;nbsp;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 20:42:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516144#M145012</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-25T20:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516148#M145018</link>
      <description>&lt;P&gt;point taken thanks for the response I will give it a shot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 21:10:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516148#M145018</guid>
      <dc:creator>irishmanjb</dc:creator>
      <dc:date>2020-08-25T21:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516153#M145021</link>
      <description>Excellent , Lets hope that this helps you and Happy splunking &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;</description>
      <pubDate>Tue, 25 Aug 2020 21:36:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516153#M145021</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-25T21:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516323#M145084</link>
      <description>&lt;P&gt;Any idea why this would not work?&amp;nbsp; The first 12 lines of my file have data and Errorcodes yet my search yields no returns.&amp;nbsp; It seems that the search is having a hard time with _time format like this.&lt;/P&gt;&lt;P&gt;_time&lt;BR /&gt;2020-08-23T21:25:33.437-0400&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;| inputlookup myfile.csv&lt;BR /&gt;| search InfoSourceID="2" OR InfoSourceID="3" ErrorCode=*&lt;BR /&gt;| eval hourmin = strftime(_time, "%H%M")&lt;BR /&gt;| where (hourmin &amp;gt;= 2124 AND hourmin &amp;lt;= 2126)&lt;BR /&gt;| streamstats reset_after=(isnull(ErrorCode)) count&lt;BR /&gt;| stats latest(eval(if(count &amp;gt;=10,_time,NULL))) as _time&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 16:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516323#M145084</guid>
      <dc:creator>irishmanjb</dc:creator>
      <dc:date>2020-08-26T16:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516325#M145085</link>
      <description>&lt;P&gt;I think that it’s better to use some other field than _time in your query when you are reading those from inputlookup (just like I did in my example). When you start to read those from index with real _time then change to it. That way it’s much easier to do and test.&amp;nbsp;&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 17:13:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516325#M145085</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-26T17:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516329#M145087</link>
      <description>&lt;P&gt;ok so that is why you used that approach&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 17:19:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516329#M145087</guid>
      <dc:creator>irishmanjb</dc:creator>
      <dc:date>2020-08-26T17:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516366#M145093</link>
      <description>&lt;P&gt;thanks for your help with this&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 19:33:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516366#M145093</guid>
      <dc:creator>irishmanjb</dc:creator>
      <dc:date>2020-08-26T19:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Specify specific time range in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516369#M145095</link>
      <description>You are welcome.</description>
      <pubDate>Wed, 26 Aug 2020 19:54:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specify-specific-time-range-in-query/m-p/516369#M145095</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-26T19:54:45Z</dc:date>
    </item>
  </channel>
</rss>

