<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk UI query start and end time in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659872#M227808</link>
    <description>&lt;P&gt;How can one add to the result of a Splunk query running on Splunk UI the time span i.e. the values one can put in earliest_time and latest_time (the earliest and latest time are coming only from the drop down of the time span in Splunk UI)&lt;/P&gt;</description>
    <pubDate>Thu, 05 Oct 2023 21:14:17 GMT</pubDate>
    <dc:creator>eranhauser</dc:creator>
    <dc:date>2023-10-05T21:14:17Z</dc:date>
    <item>
      <title>Splunk UI query start and end time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659872#M227808</link>
      <description>&lt;P&gt;How can one add to the result of a Splunk query running on Splunk UI the time span i.e. the values one can put in earliest_time and latest_time (the earliest and latest time are coming only from the drop down of the time span in Splunk UI)&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 21:14:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659872#M227808</guid>
      <dc:creator>eranhauser</dc:creator>
      <dc:date>2023-10-05T21:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UI query start and end time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659882#M227810</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241831"&gt;@eranhauser&lt;/a&gt;&amp;nbsp;... i am sorry, i am unable to understand your query..&amp;nbsp;&lt;/P&gt;&lt;P&gt;you are running a search.. Would you like to know exactly when the SPL started to run and exactly when the SPL finished running? or you want to include these values inside the search itself?&lt;/P&gt;&lt;P&gt;Did you check the "Inspect Job" ?!?!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 21:36:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659882#M227810</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-10-05T21:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UI query start and end time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659888#M227815</link>
      <description>&lt;P&gt;I am going to run my query using a scheduler so I want to record in each event the time span the query used to capture that event&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 23:13:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659888#M227815</guid>
      <dc:creator>eranhauser</dc:creator>
      <dc:date>2023-10-05T23:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UI query start and end time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659891#M227817</link>
      <description>&lt;P&gt;Please run that scheduled search query and then check the "inspect job".. you will get more than you wanted. thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 00:02:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659891#M227817</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-10-06T00:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UI query start and end time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659892#M227818</link>
      <description>&lt;P&gt;I need these times in the event itself&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 00:04:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659892#M227818</guid>
      <dc:creator>eranhauser</dc:creator>
      <dc:date>2023-10-06T00:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UI query start and end time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659894#M227820</link>
      <description>&lt;P&gt;then you should invent the timemachine, get the results, go back in time and update the results inside the event itself. &amp;lt;bootstrap paradox&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 00:14:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-UI-query-start-and-end-time/m-p/659894#M227820</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-10-06T00:14:23Z</dc:date>
    </item>
  </channel>
</rss>

