<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple time searches in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Multiple-time-searches/m-p/669044#M229482</link>
    <description>&lt;P&gt;I have the below search and I'm trying to search for different time periods within each search.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So for example msg="*Completed *" is using the timepicker input.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to search for data one hour before the timepicker search (so this should be dynamic) for msg="*First *"&lt;/P&gt;&lt;P&gt;I'm not sure if this is possible.&lt;/P&gt;&lt;P&gt;I'm comparing these two searches and the initial log msg="*First*" can occur several minutes before the msg=*Completed*" log. So when I compare some of these log messages get cut off depending on when I select my timepicker. I would like to search for these message 1 hour before my timepicker selection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Long term this search will go into a splunk dashboard.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(index=color name IN ("green","blue")  msg="*First *" ```earliest="11/09/2023:09:00:00" latest="11/09/2023:12:59:59"```)
OR
(index=color name IN ("blue2","green2") msg="*Completed *")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Nov 2023 18:16:54 GMT</pubDate>
    <dc:creator>MrJohn230</dc:creator>
    <dc:date>2023-11-17T18:16:54Z</dc:date>
    <item>
      <title>Multiple time searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-time-searches/m-p/669044#M229482</link>
      <description>&lt;P&gt;I have the below search and I'm trying to search for different time periods within each search.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So for example msg="*Completed *" is using the timepicker input.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to search for data one hour before the timepicker search (so this should be dynamic) for msg="*First *"&lt;/P&gt;&lt;P&gt;I'm not sure if this is possible.&lt;/P&gt;&lt;P&gt;I'm comparing these two searches and the initial log msg="*First*" can occur several minutes before the msg=*Completed*" log. So when I compare some of these log messages get cut off depending on when I select my timepicker. I would like to search for these message 1 hour before my timepicker selection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Long term this search will go into a splunk dashboard.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(index=color name IN ("green","blue")  msg="*First *" ```earliest="11/09/2023:09:00:00" latest="11/09/2023:12:59:59"```)
OR
(index=color name IN ("blue2","green2") msg="*Completed *")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 18:16:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-time-searches/m-p/669044#M229482</guid>
      <dc:creator>MrJohn230</dc:creator>
      <dc:date>2023-11-17T18:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple time searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-time-searches/m-p/669056#M229487</link>
      <description>Hi&lt;BR /&gt;This is doable. You could e.g. add several time pickers on your dashboards and add those to your queries as tokens. I cannot recall now if this needs you to add additional tokens to set those limits correctly in your search?&lt;BR /&gt;r. Ismo</description>
      <pubDate>Fri, 17 Nov 2023 19:48:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-time-searches/m-p/669056#M229487</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-17T19:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple time searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-time-searches/m-p/669128#M229514</link>
      <description>&lt;P&gt;It's easy enough in a dashboard to create one time range for searches based on an input time range set in the time picker. You just create a global search that uses time picker time and then use addinfo to get the epoch range of the time picker and do calculations on that and set appropriate tokens.&lt;/P&gt;&lt;P&gt;Here are a some example posts that talk about it in dashboards.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-count-events-for-specific-time-period-now-and-7-days/m-p/633364/highlight/true#M108437" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-to-count-events-for-specific-time-period-now-and-7-days/m-p/633364/highlight/true#M108437&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-dynamic-label-based-on-time-input-change/m-p/629246/highlight/true#M51614" target="_blank"&gt;https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-dynamic-label-based-on-time-input-change/m-p/629246/highlight/true#M51614&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Dashboards-Visualizations/How-convert-input-date-time-to-token-values-and-display-on/m-p/612985/highlight/true#M50281" target="_blank"&gt;https://community.splunk.com/t5/Dashboards-Visualizations/How-convert-input-date-time-to-token-values-and-display-on/m-p/612985/highlight/true#M50281&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 00:32:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-time-searches/m-p/669128#M229514</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-11-20T00:32:05Z</dc:date>
    </item>
  </channel>
</rss>

