<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic earliest=-1w does not work in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221730#M188172</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;
I have the following simple search.&lt;BR /&gt;
sourcetype=ib:reserved1 source=ib:user:user_login index=ib_security earliest=-1w&lt;/P&gt;

&lt;P&gt;When i run this search i do not get results. But when i remove the earliest command, I get the results. &lt;BR /&gt;
All the results have todays date as time. So it should return result when I put earliest as 1 week back.&lt;/P&gt;

&lt;P&gt;Why is earliest not working&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 07:50:07 GMT</pubDate>
    <dc:creator>GauriSplunk</dc:creator>
    <dc:date>2020-09-29T07:50:07Z</dc:date>
    <item>
      <title>earliest=-1w does not work</title>
      <link>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221730#M188172</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I have the following simple search.&lt;BR /&gt;
sourcetype=ib:reserved1 source=ib:user:user_login index=ib_security earliest=-1w&lt;/P&gt;

&lt;P&gt;When i run this search i do not get results. But when i remove the earliest command, I get the results. &lt;BR /&gt;
All the results have todays date as time. So it should return result when I put earliest as 1 week back.&lt;/P&gt;

&lt;P&gt;Why is earliest not working&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221730#M188172</guid>
      <dc:creator>GauriSplunk</dc:creator>
      <dc:date>2020-09-29T07:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: earliest=-1w does not work</title>
      <link>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221731#M188173</link>
      <description>&lt;P&gt;Does putting around source &amp;amp; sourcetype  make any difference? &lt;/P&gt;

&lt;P&gt;sourcetype="ib:reserved1" source="ib:user:user_login" index="ib_security" earliest=-1w&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:49:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221731#M188173</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2020-09-29T07:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: earliest=-1w does not work</title>
      <link>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221732#M188174</link>
      <description>&lt;P&gt;No, I tried again with and without quotes around various pieces but just can't make it misbehave.  I've also tried the various pieces individually and in various combinations.  If GauriSplunk can reproduce this at will, I expect Splunk Support will definately want to take a look at this.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Nov 2015 20:27:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221732#M188174</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2015-11-08T20:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: earliest=-1w does not work</title>
      <link>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221733#M188175</link>
      <description>&lt;P&gt;I am sorry, I was careless and made a silly mistake in my testing and retract my confirmation of this problem.  I am unable to reproduce it.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 06:27:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221733#M188175</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-11-09T06:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: earliest=-1w does not work</title>
      <link>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221734#M188176</link>
      <description>&lt;P&gt;the date on my events was greater than current date. (maybe the date on that machine was wrongly set).&lt;BR /&gt;
So I believe it takes latest as now by default.&lt;BR /&gt;
so earliest=-1w and latest = now , it didnt match the events.&lt;/P&gt;

&lt;P&gt;If it didnt take any default value for latest, it would have worked.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 17:39:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221734#M188176</guid>
      <dc:creator>GauriSplunk</dc:creator>
      <dc:date>2015-11-09T17:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: earliest=-1w does not work</title>
      <link>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221735#M188177</link>
      <description>&lt;P&gt;Hi GauriSplunk,&lt;/P&gt;

&lt;P&gt;I converted your comment to an answer since it looks like you solved your time stamp issue/problem by setting a &lt;CODE&gt;latest&lt;/CODE&gt; value in the search. Is that correct?&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 20:16:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221735#M188177</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-11-09T20:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: earliest=-1w does not work</title>
      <link>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221736#M188178</link>
      <description>&lt;P&gt;Running this search on Splunk 6.3.1 on Linux works:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="_internal" sourcetype="splunkd" source="*metrics.log" earliest=-1w
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It will return &lt;CODE&gt;450,072 events (before 11/10/15 9:19:03.378 AM)&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 20:20:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221736#M188178</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-11-09T20:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: earliest=-1w does not work</title>
      <link>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221737#M188179</link>
      <description>&lt;P&gt;yes. thanks&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 21:02:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/earliest-1w-does-not-work/m-p/221737#M188179</guid>
      <dc:creator>GauriSplunk</dc:creator>
      <dc:date>2015-11-09T21:02:28Z</dc:date>
    </item>
  </channel>
</rss>

