<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: what is  apiStartTime='ZERO_TIME' in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75491#M19089</link>
    <description>&lt;P&gt;No problem  - please post if you figure it out...&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jun 2013 01:15:50 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2013-06-27T01:15:50Z</dc:date>
    <item>
      <title>what is  apiStartTime='ZERO_TIME'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75485#M19083</link>
      <description>&lt;P&gt;I have been investigating excessively expensive searches by querying the audit log, and I came across one that has this time range: &lt;BR /&gt;
apiStartTime='ZERO_TIME', apiEndTime='ZERO_TIME'&lt;/P&gt;

&lt;P&gt;Anyone knows what this means?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:10:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75485#M19083</guid>
      <dc:creator>sansay</dc:creator>
      <dc:date>2020-09-28T14:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: what is  apiStartTime='ZERO_TIME'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75486#M19084</link>
      <description>&lt;P&gt;The audit log captures the time range of the search. As a Splunk user, you specify the time range by using the pull-down menu (or by using the &lt;CODE&gt;earliest&lt;/CODE&gt; and &lt;CODE&gt;latest&lt;/CODE&gt; keywords). When Splunk processes the search, it calculates the actual time that should be searched. &lt;CODE&gt;apiStartTime&lt;/CODE&gt; represents the earliest time, and &lt;CODE&gt;apiEndTime&lt;/CODE&gt; represents the latest time.&lt;/P&gt;

&lt;P&gt;EDIT - in my original answer, I said  &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;apiStartTime='ZERO_TIME', apiEndTime='ZERO_TIME'&lt;/CODE&gt; means that the search ran over &lt;STRONG&gt;All Time&lt;/STRONG&gt;. It makes sense that this would be an excessively expensive search.&lt;/P&gt;

&lt;P&gt;but this appears not to be the case.&lt;BR /&gt;&lt;BR /&gt;
END EDIT&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 23:39:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75486#M19084</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-06-25T23:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: what is  apiStartTime='ZERO_TIME'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75487#M19085</link>
      <description>&lt;P&gt;Thank you very much lguinn.&lt;BR /&gt;
The weird thing is that I disabled the "All time" from the GUI. And the user, from being the previous Splunk admin knows very well not to run "All time" queries. And he confirmed that when asked. So how else could this happen?&lt;/P&gt;

&lt;P&gt;Is there any way I can get the exact query that was executed, ie, with the time range specified by the user?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2013 00:10:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75487#M19085</guid>
      <dc:creator>sansay</dc:creator>
      <dc:date>2013-06-26T00:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: what is  apiStartTime='ZERO_TIME'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75488#M19086</link>
      <description>&lt;P&gt;This gets weirder and weirder, according to my last search, and if  apiStartTime='ZERO_TIME', apiEndTime='ZERO_TIME' means "All time", even I ran "All time" queries. This is starting to sound more and more like a bug.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75488#M19086</guid>
      <dc:creator>sansay</dc:creator>
      <dc:date>2020-09-28T14:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: what is  apiStartTime='ZERO_TIME'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75489#M19087</link>
      <description>&lt;P&gt;Perhaps I am wrong. Could this have been something run by Splunk internally?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2013 00:58:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75489#M19087</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-06-26T00:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: what is  apiStartTime='ZERO_TIME'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75490#M19088</link>
      <description>&lt;P&gt;Sorry but, indeed, it seems that your original answer is wrong. &lt;BR /&gt;
A simpler search, without apiStartTime='ZERO_TIME' apiEndTime='ZERO_TIME', returns a bunch of other records, including the very same query, with the exact time range selected by the user. And this query occured just microseconds before the one with ZERO_TIME. So it must be something splunk does, but because it happens all the time it can't mean that it's the "All time" time range that was used.&lt;BR /&gt;
So I have to remove the point. I will add this in a splunk ticket I opened to resolve cold storage searches that take our system down.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:10:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75490#M19088</guid>
      <dc:creator>sansay</dc:creator>
      <dc:date>2020-09-28T14:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: what is  apiStartTime='ZERO_TIME'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75491#M19089</link>
      <description>&lt;P&gt;No problem  - please post if you figure it out...&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2013 01:15:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75491#M19089</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-06-27T01:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: what is  apiStartTime='ZERO_TIME'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75492#M19090</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15446"&gt;@sansay&lt;/a&gt; ,&lt;BR /&gt;
Could you please let me know wht this actually means if you are aware of it now?&lt;/P&gt;

&lt;P&gt;apiStartTime='ZERO_TIME', apiEndTime='ZERO_TIME'&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:07:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75492#M19090</guid>
      <dc:creator>sarnagar</dc:creator>
      <dc:date>2020-09-29T13:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: what is  apiStartTime='ZERO_TIME'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75493#M19091</link>
      <description>&lt;P&gt;Sorry but no, I haven't figured it out. I haven't had the time to even think about this issue.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2017 23:13:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75493#M19091</guid>
      <dc:creator>sansay</dc:creator>
      <dc:date>2017-03-08T23:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: what is  apiStartTime='ZERO_TIME'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75494#M19092</link>
      <description>&lt;P&gt;These could be real time searches. &lt;BR /&gt;
I ran a search like "index=*" for 30 seconds realtime, and the apiStartTime was displayed as Zero_time&lt;/P&gt;

&lt;P&gt;search  total_run_time  _time   apiStartTime    apiEndTime  search_type user&lt;BR /&gt;
search index=*      2018-03-20 10:28:09.913 ZERO_TIME   ZERO_TIME   ad hoc  test_user01&lt;BR /&gt;
search index=*      2018-03-20 10:28:13.560 ZERO_TIME   ZERO_TIME   ad hoc  test_user01&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:32:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/what-is-apiStartTime-ZERO-TIME/m-p/75494#M19092</guid>
      <dc:creator>dvg06</dc:creator>
      <dc:date>2020-09-29T18:32:35Z</dc:date>
    </item>
  </channel>
</rss>

