<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to see only the events where &amp;quot;firstSeen&amp;quot; is within the last 7 days? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-only-the-events-where-quot-firstSeen-quot-is-within/m-p/622463#M216380</link>
    <description>&lt;P&gt;I have this dataset in SPlunk,&amp;nbsp; I am trying to see only the events where "firstSeen" is within the last 7 days.&lt;/P&gt;
&lt;P&gt;I tried to | where firstSeen&amp;lt;7d&amp;nbsp; but that didn't work also.&lt;/P&gt;
&lt;TABLE width="1325"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="87"&gt;state&lt;/TD&gt;
&lt;TD width="87"&gt;Age&lt;/TD&gt;
&lt;TD width="280"&gt;dnsName&lt;/TD&gt;
&lt;TD width="207"&gt;firstSeen&lt;/TD&gt;
&lt;TD width="227"&gt;ip&lt;/TD&gt;
&lt;TD width="87"&gt;lastSeen&lt;/TD&gt;
&lt;TD width="165"&gt;severity&lt;/TD&gt;
&lt;TD width="185"&gt;pluginID&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;32.49&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;10.102.10.1&lt;/TD&gt;
&lt;TD&gt;29-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;10180&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;Cat&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;10.102.1.23&lt;/TD&gt;
&lt;TD&gt;29-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;11219&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;34.06&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;22-Nov-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;29-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;19506&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;5.6&lt;/TD&gt;
&lt;TD&gt;Dog&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;23-Nov-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;168007&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;22.65&lt;/TD&gt;
&lt;TD&gt;Lion&lt;/TD&gt;
&lt;TD&gt;6-Nov-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;166958&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;31.64&lt;/TD&gt;
&lt;TD&gt;tiger&lt;/TD&gt;
&lt;TD&gt;28-Oct-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;166602&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;120.63&lt;/TD&gt;
&lt;TD&gt;giraf&lt;/TD&gt;
&lt;TD&gt;25-Nov-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;163588&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;68.47&lt;/TD&gt;
&lt;TD&gt;leap&lt;/TD&gt;
&lt;TD&gt;21-Sep-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;163489&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;68.47&lt;/TD&gt;
&lt;TD&gt;big dog&lt;/TD&gt;
&lt;TD&gt;21-Sep-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;163488&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
    <pubDate>Tue, 29 Nov 2022 17:48:42 GMT</pubDate>
    <dc:creator>marceldera</dc:creator>
    <dc:date>2022-11-29T17:48:42Z</dc:date>
    <item>
      <title>How to see only the events where "firstSeen" is within the last 7 days?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-only-the-events-where-quot-firstSeen-quot-is-within/m-p/622463#M216380</link>
      <description>&lt;P&gt;I have this dataset in SPlunk,&amp;nbsp; I am trying to see only the events where "firstSeen" is within the last 7 days.&lt;/P&gt;
&lt;P&gt;I tried to | where firstSeen&amp;lt;7d&amp;nbsp; but that didn't work also.&lt;/P&gt;
&lt;TABLE width="1325"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="87"&gt;state&lt;/TD&gt;
&lt;TD width="87"&gt;Age&lt;/TD&gt;
&lt;TD width="280"&gt;dnsName&lt;/TD&gt;
&lt;TD width="207"&gt;firstSeen&lt;/TD&gt;
&lt;TD width="227"&gt;ip&lt;/TD&gt;
&lt;TD width="87"&gt;lastSeen&lt;/TD&gt;
&lt;TD width="165"&gt;severity&lt;/TD&gt;
&lt;TD width="185"&gt;pluginID&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;32.49&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;10.102.10.1&lt;/TD&gt;
&lt;TD&gt;29-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;10180&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;Cat&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;10.102.1.23&lt;/TD&gt;
&lt;TD&gt;29-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;11219&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;34.06&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;22-Nov-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;29-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;19506&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;5.6&lt;/TD&gt;
&lt;TD&gt;Dog&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;23-Nov-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;168007&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;22.65&lt;/TD&gt;
&lt;TD&gt;Lion&lt;/TD&gt;
&lt;TD&gt;6-Nov-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;166958&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;31.64&lt;/TD&gt;
&lt;TD&gt;tiger&lt;/TD&gt;
&lt;TD&gt;28-Oct-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;166602&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;120.63&lt;/TD&gt;
&lt;TD&gt;giraf&lt;/TD&gt;
&lt;TD&gt;25-Nov-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;163588&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;68.47&lt;/TD&gt;
&lt;TD&gt;leap&lt;/TD&gt;
&lt;TD&gt;21-Sep-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;163489&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;open&lt;/TD&gt;
&lt;TD&gt;68.47&lt;/TD&gt;
&lt;TD&gt;big dog&lt;/TD&gt;
&lt;TD&gt;21-Sep-22&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;28-Nov-22&lt;/TD&gt;
&lt;TD&gt;informational&lt;/TD&gt;
&lt;TD&gt;163488&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 29 Nov 2022 17:48:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-see-only-the-events-where-quot-firstSeen-quot-is-within/m-p/622463#M216380</guid>
      <dc:creator>marceldera</dc:creator>
      <dc:date>2022-11-29T17:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to see only the events where "firstSeen" is within the last 7 days?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-only-the-events-where-quot-firstSeen-quot-is-within/m-p/622474#M216386</link>
      <description>&lt;P&gt;It's hard to be certain from this table but the firstSeen will most probably be a string. You have to parse it with strptime to a nummerical timestamp. Then you simply filter with&lt;/P&gt;&lt;PRE&gt;| where your_timestamp&amp;gt;now()-7*86400&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Nov 2022 18:06:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-see-only-the-events-where-quot-firstSeen-quot-is-within/m-p/622474#M216386</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-11-29T18:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to see only the events where "firstSeen" is within the last 7 days?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-only-the-events-where-quot-firstSeen-quot-is-within/m-p/622481#M216390</link>
      <description>&lt;P&gt;This is the query that i used, it is returning no results&lt;/P&gt;&lt;P&gt;index=tenable* sourcetype="*" | where pluginID &amp;lt;1000000&lt;BR /&gt;| eval firstSeen=strftime(firstSeen, "%m/%d/%Y %H:%M:%S")&lt;BR /&gt;| eval lastSeen=strftime(lastSeen, "%m/%d/%Y %H:%M:%S")&lt;BR /&gt;| eval discovery = strptime(lastSeen, "%m/%d/%Y %H:%M:%S") - strptime(firstSeen, "%m/%d/%Y %H:%M:%S")&lt;BR /&gt;| eval Age = round(discovery / 86400, 2)&lt;BR /&gt;| eval firstSeen =strftime(strptime(firstSeen,"%m/%d/%Y %H:%M:%S"),"%d-%B-%y")&lt;BR /&gt;| eval lastSeen =strftime(strptime(lastSeen,"%m/%d/%Y %H:%M:%S"),"%d-%B-%y")&lt;BR /&gt;| dedup pluginID&lt;BR /&gt;| where firstSeen&amp;gt;now()-7*86400&lt;BR /&gt;| table State Age dnsName firstSeen ip lastSeen severity pluginID&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 18:20:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-see-only-the-events-where-quot-firstSeen-quot-is-within/m-p/622481#M216390</guid>
      <dc:creator>marceldera</dc:creator>
      <dc:date>2022-11-29T18:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to see only the events where "firstSeen" is within the last 7 days?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-only-the-events-where-quot-firstSeen-quot-is-within/m-p/622495#M216403</link>
      <description>&lt;P&gt;How is it that your "dataset" contains a field "Age" but you are also calculating it based on a field that doesn't exist in your dataset, namely "lastSeen"? &amp;nbsp;Is that table what is output, not what is your dataset?&lt;/P&gt;&lt;P&gt;Without knowing what your raw data looks like, no one can tell you what to expect.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 19:06:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-see-only-the-events-where-quot-firstSeen-quot-is-within/m-p/622495#M216403</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-11-29T19:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to see only the events where "firstSeen" is within the last 7 days?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-only-the-events-where-quot-firstSeen-quot-is-within/m-p/622497#M216404</link>
      <description>&lt;P&gt;Purely based on your sample code, there are several mistakes; the most serious one is to trying to calculate numeric value based on output from strftime which is a string.&lt;/P&gt;&lt;P&gt;If I take blind faith in your code, I'd modify it to&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=tenable* sourcetype="*" | where pluginID &amp;lt;1000000
| dedup pluginID
| eval discovery = lastSeen - firstSeen
| eval Age = round(discovery / 86400, 2)
| where relative_time(firstSeen, "+7d") &amp;lt; now()
| fieldformat firstSeen =strftime(firstSeen,"%d-%B-%y")
| fieldformat lastSeen =strftime(lastSeen,"%d-%B-%y")
| table State Age dnsName firstSeen ip lastSeen severity pluginID&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 29 Nov 2022 19:12:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-see-only-the-events-where-quot-firstSeen-quot-is-within/m-p/622497#M216404</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-11-29T19:12:19Z</dc:date>
    </item>
  </channel>
</rss>

