<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue in Splunk with the time brackets in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Issue-in-Splunk-with-the-time-brackets/m-p/712787#M240404</link>
    <description>&lt;P&gt;&lt;BR /&gt;Hello Splunkers!!&lt;/P&gt;&lt;P&gt;We recently migrated Splunk from version &lt;STRONG&gt;8.1.1 to 9.1.1 and encountered the following errors:&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;ERROR TimeParser [&lt;SPAN class=""&gt;12568 SchedulerThread] - Invalid value &lt;SPAN class=""&gt;"`bin" &lt;SPAN class=""&gt;for &lt;SPAN class=""&gt;time term &lt;SPAN class=""&gt;'latest' ERROR TimeParser [&lt;SPAN class=""&gt;12568 SchedulerThread] - Invalid value &lt;SPAN class=""&gt;"$info_max_time_2$" &lt;SPAN class=""&gt;for &lt;SPAN class=""&gt;time term &lt;SPAN class=""&gt;'latest'&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;Upon reviewing the &lt;STRONG&gt;Splunk 9.1.1 release notes, I found that this issue is listed as a known bug. Has anyone observed and resolved this issue before?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If you have implemented a fix, could you share the specific configuration changes or workarounds applied? Any insights on where to check (e.g., saved searches, scheduled reports, or specific configurations) would be greatly appreciated.&lt;BR /&gt;&lt;BR /&gt;Below is the screenshot of the known bug in 9.1.1&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1740738441912.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34749i9B3B6B0B688DBFA2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1740738441912.png" alt="uagraw01_0-1740738441912.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 28 Feb 2025 10:28:10 GMT</pubDate>
    <dc:creator>uagraw01</dc:creator>
    <dc:date>2025-02-28T10:28:10Z</dc:date>
    <item>
      <title>Issue in Splunk with the time brackets</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-in-Splunk-with-the-time-brackets/m-p/712787#M240404</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hello Splunkers!!&lt;/P&gt;&lt;P&gt;We recently migrated Splunk from version &lt;STRONG&gt;8.1.1 to 9.1.1 and encountered the following errors:&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN&gt;ERROR TimeParser [&lt;SPAN class=""&gt;12568 SchedulerThread] - Invalid value &lt;SPAN class=""&gt;"`bin" &lt;SPAN class=""&gt;for &lt;SPAN class=""&gt;time term &lt;SPAN class=""&gt;'latest' ERROR TimeParser [&lt;SPAN class=""&gt;12568 SchedulerThread] - Invalid value &lt;SPAN class=""&gt;"$info_max_time_2$" &lt;SPAN class=""&gt;for &lt;SPAN class=""&gt;time term &lt;SPAN class=""&gt;'latest'&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;Upon reviewing the &lt;STRONG&gt;Splunk 9.1.1 release notes, I found that this issue is listed as a known bug. Has anyone observed and resolved this issue before?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If you have implemented a fix, could you share the specific configuration changes or workarounds applied? Any insights on where to check (e.g., saved searches, scheduled reports, or specific configurations) would be greatly appreciated.&lt;BR /&gt;&lt;BR /&gt;Below is the screenshot of the known bug in 9.1.1&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1740738441912.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34749i9B3B6B0B688DBFA2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1740738441912.png" alt="uagraw01_0-1740738441912.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 28 Feb 2025 10:28:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-in-Splunk-with-the-time-brackets/m-p/712787#M240404</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2025-02-28T10:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: Issue in Splunk with the time brackets</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-in-Splunk-with-the-time-brackets/m-p/712792#M240407</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im not sure if the bug is related to the issue you are having, as the bug relates to the latest=now being omitted from searches where earliest=&amp;lt;something&amp;gt; is used.&lt;/P&gt;&lt;P&gt;Is this a drilldown search from Enterprise Security? Or something else? Are you able to find the full search that was executed? It is odd that&amp;nbsp;&lt;SPAN&gt;info_max_time_2 looks to contain "`bin" (according to the output) so it would be good to understand how that value could have got there!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you cant find the search, I'd look into _audit for 5 seconds eitherside of that error timestamp and start filtering down from there, maybe look for keywords like "bin" as its appears in the error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Let us know what you find so we can help further!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 11:14:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-in-Splunk-with-the-time-brackets/m-p/712792#M240407</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-02-28T11:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Issue in Splunk with the time brackets</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-in-Splunk-with-the-time-brackets/m-p/712836#M240428</link>
      <description>I think that &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt; is right and this is not exactly the reason for your issue.&lt;BR /&gt;&lt;BR /&gt;Can you share your dashboard where this issue is with us or at least that part which generate that error? Please use code block for that dashboard (it is link/icon &amp;lt;/&amp;gt; in editor).&lt;BR /&gt;&lt;BR /&gt;That SPL-237902 seems to be still there even in 9.4.1.</description>
      <pubDate>Fri, 28 Feb 2025 15:21:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-in-Splunk-with-the-time-brackets/m-p/712836#M240428</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-02-28T15:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: Issue in Splunk with the time brackets</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-in-Splunk-with-the-time-brackets/m-p/740520#M240449</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;`search_on_index_time("`$input_macro$`", $span$)` | fields _time source id | bin _time AS earliest_time span=$span$ | eval latest_time=earliest_time+$span$ | stats values(id) AS ids, values(source) AS sources BY earliest_time latest_time | eval ids="\"".mvjoin(ids, "\",\"")."\"", sources="\"".mvjoin(sources, "\",\"")."\"" | `fillnull(value="", fields="earliest_time latest_time input_macro summarize_macro sources ids")` | map maxsearches=20000 search="search earliest=$earliest_time$ latest=$latest_time$ `$input_macro$(\"$sources$\",\"$ids$\")` | `$summarize_macro$($earliest_time$, $latest_time$)` | eval _time=$earliest_time$" | appendpipe [|where source="route" | collect index=$index$ source="route" | where false()] | appendpipe [|where source="system" | collect index=$index$ source="system" | where false()]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am using a macro in one of my saved searches and encountering the below error in Splunk. Based on the known issue, what changes should I make to the macro to resolve this error and eliminate the message?&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;&lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class=""&gt;TimeParser&lt;/SPAN&gt; [&lt;SPAN class=""&gt;24352&lt;/SPAN&gt; &lt;SPAN class=""&gt;SchedulerThread&lt;/SPAN&gt;] &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Invalid&lt;/SPAN&gt; &lt;SPAN class=""&gt;value&lt;/SPAN&gt; "&lt;SPAN class=""&gt;$latest_time$&lt;/SPAN&gt;" &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;time&lt;/SPAN&gt; &lt;SPAN class=""&gt;term&lt;/SPAN&gt; &lt;SPAN class=""&gt;'&lt;SPAN class=""&gt;latest'&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 03:50:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-in-Splunk-with-the-time-brackets/m-p/740520#M240449</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2025-03-03T03:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: Issue in Splunk with the time brackets</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-in-Splunk-with-the-time-brackets/m-p/740534#M240450</link>
      <description>&lt;P&gt;It seems that there are so many macros etc. that we cannot say directly almost anything about it.&amp;nbsp;&lt;BR /&gt;The only thing what I can said is that you should try to resolve it by go step by step forward and try to find why latest_time haven’t have value defined.&lt;/P&gt;&lt;P&gt;This app&amp;nbsp;&lt;A href="https://classic.splunkbase.splunk.com/app/1603/" target="_blank"&gt;https://classic.splunkbase.splunk.com/app/1603/&lt;/A&gt;&amp;nbsp;can help you to identify what values you have defined in your code. Just add script=… in your dashboard and this shows values to you. See e.g.&amp;nbsp;&lt;A href="https://data-findings.com/wp-content/uploads/2024/09/HSUG-20240903-Tiia-Ojares.pdf" target="_blank"&gt;https://data-findings.com/wp-content/uploads/2024/09/HSUG-20240903-Tiia-Ojares.pdf&lt;/A&gt;&amp;nbsp;page 4.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 06:56:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-in-Splunk-with-the-time-brackets/m-p/740534#M240450</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-03-03T06:56:56Z</dc:date>
    </item>
  </channel>
</rss>

