<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log searching Splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Log-searching-Splunk/m-p/681480#M232876</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263556"&gt;@marnall&lt;/a&gt;&amp;nbsp;@Not really, it’s like if I’m running the search for last 24 hrs, I’d like to see the data for now()+1d.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Mar 2024 02:05:39 GMT</pubDate>
    <dc:creator>av_</dc:creator>
    <dc:date>2024-03-21T02:05:39Z</dc:date>
    <item>
      <title>Log searching Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Log-searching-Splunk/m-p/681387#M232837</link>
      <description>&lt;P&gt;I am searching some logs in an application for the last 24 hours (or any time range the user has selected). Is it possible to search the same logs in another application for the next day?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eg: if the user has selected the time range as last one hour, can I see the trajectory of those logs over a period of next day?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 13:21:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Log-searching-Splunk/m-p/681387#M232837</guid>
      <dc:creator>av_</dc:creator>
      <dc:date>2024-03-20T13:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: Log searching Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Log-searching-Splunk/m-p/681462#M232870</link>
      <description>&lt;P&gt;As in running the same search that another user has previously run, but in a different time period?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 21:48:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Log-searching-Splunk/m-p/681462#M232870</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-03-20T21:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Log searching Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Log-searching-Splunk/m-p/681480#M232876</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263556"&gt;@marnall&lt;/a&gt;&amp;nbsp;@Not really, it’s like if I’m running the search for last 24 hrs, I’d like to see the data for now()+1d.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 02:05:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Log-searching-Splunk/m-p/681480#M232876</guid>
      <dc:creator>av_</dc:creator>
      <dc:date>2024-03-21T02:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Log searching Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Log-searching-Splunk/m-p/681487#M232879</link>
      <description>&lt;P&gt;When you say "in another application" what do you mean&lt;/P&gt;&lt;P&gt;The predict command can be used to predict future trends&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.0.2305/SearchReference/predict" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.1.2312/SearchReference/Predict&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 05:27:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Log-searching-Splunk/m-p/681487#M232879</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-03-21T05:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: Log searching Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Log-searching-Splunk/m-p/681621#M232922</link>
      <description>&lt;P&gt;Probably the best thing for that, as&amp;nbsp;bowesmana suggested, is the predict command, which would estimate what the data may look like in the future based on its behavior in the past.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unless you have data with timestamps in the future, you can't actually look at future data. now()+1d should be empty.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 20:56:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Log-searching-Splunk/m-p/681621#M232922</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-03-21T20:56:40Z</dc:date>
    </item>
  </channel>
</rss>

