<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About time modifier in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/About-time-modifier/m-p/173464#M49752</link>
    <description>&lt;P&gt;I doubt there actually is a day of overlap, because both are pointing to midnight / 00:00 that day.&lt;/P&gt;</description>
    <pubDate>Tue, 10 Dec 2013 13:43:10 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2013-12-10T13:43:10Z</dc:date>
    <item>
      <title>About time modifier</title>
      <link>https://community.splunk.com/t5/Splunk-Search/About-time-modifier/m-p/173463#M49751</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;

&lt;P&gt;I am considering to use summary index to effectively search massive data.&lt;BR /&gt;
To do this, I am considering to set saved search and use time modifier to slide the time range ever time&lt;BR /&gt;
the search is executed.&lt;/P&gt;

&lt;P&gt;what I am trying to set is &lt;/P&gt;

&lt;P&gt;earliest = @quarter-6mon latest=@quarter-3mon&lt;/P&gt;

&lt;P&gt;I am planning to  execute the above time modifier every calendar quarter.&lt;BR /&gt;
I believe there will be a point where it is overlapped by both search.&lt;/P&gt;

&lt;P&gt;For example,&lt;/P&gt;

&lt;P&gt;1st search is executed at 2013/4 the time modifier will be,&lt;BR /&gt;
2012/10/1  - 2013/1/1&lt;/P&gt;

&lt;P&gt;Next time executed,&lt;BR /&gt;
2013/1/1 - 2013/4/1&lt;/P&gt;

&lt;P&gt;So 2013/1/1 is overlapped .&lt;/P&gt;

&lt;P&gt;Would there be any way to elude this ?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Yu&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2013 12:47:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/About-time-modifier/m-p/173463#M49751</guid>
      <dc:creator>yuwtennis</dc:creator>
      <dc:date>2013-12-10T12:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: About time modifier</title>
      <link>https://community.splunk.com/t5/Splunk-Search/About-time-modifier/m-p/173464#M49752</link>
      <description>&lt;P&gt;I doubt there actually is a day of overlap, because both are pointing to midnight / 00:00 that day.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2013 13:43:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/About-time-modifier/m-p/173464#M49752</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-12-10T13:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: About time modifier</title>
      <link>https://community.splunk.com/t5/Splunk-Search/About-time-modifier/m-p/173465#M49753</link>
      <description>&lt;P&gt;Hello martin_mueller.&lt;/P&gt;

&lt;P&gt;Thank you for the comment.&lt;/P&gt;

&lt;P&gt;Wouldn't events that has "2013/1/1 00:00" be overlapped?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Yu&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 06:27:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/About-time-modifier/m-p/173465#M49753</guid>
      <dc:creator>yuwtennis</dc:creator>
      <dc:date>2013-12-11T06:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: About time modifier</title>
      <link>https://community.splunk.com/t5/Splunk-Search/About-time-modifier/m-p/173466#M49754</link>
      <description>&lt;P&gt;No. Mathematically speaking, the timerange searched is the interval [earliest, latest). In other words, events occurring at the earliest timestamp are included while events occurring at the latest timestamp are not.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 08:20:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/About-time-modifier/m-p/173466#M49754</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-12-11T08:20:39Z</dc:date>
    </item>
  </channel>
</rss>

