<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Specifying a date range in field extraction window in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228335#M67480</link>
    <description>&lt;P&gt;What version of Splunk you're using??&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jan 2016 20:38:10 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2016-01-18T20:38:10Z</dc:date>
    <item>
      <title>Specifying a date range in field extraction window</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228334#M67479</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;

&lt;P&gt;I am looking through a very very very large log of files for events.  In the normal search screen, you can specify date ranges for your search, but in the field extraction screen, I cannot specify a range of dates to search through when I am searching for the sample event using the filter, so it searches through all (something like 200 million) events in order to find the string I am searching for.  I know the date the event occurs on, and can find it in a normal  search instantly, but not with the field extraction screen.&lt;/P&gt;

&lt;P&gt;I have tried adding &lt;CODE&gt;earliest=10/19/2009:0:0:0 latest=01/17/2016:0:0:0&lt;/CODE&gt; to find the events, but it always just returns &lt;CODE&gt;0 events (before 1/18/16 7:29:48.000 PM)&lt;/CODE&gt;.  Is there a way to specify date ranges inside of the field extraction filter so that I dont have to filter through everything?&lt;/P&gt;

&lt;P&gt;When I add that filter from above, I am searching for an event structured like this &lt;CODE&gt;Jan 15 13:54:23 |actual error message|&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 19:31:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228334#M67479</guid>
      <dc:creator>Spiere</dc:creator>
      <dc:date>2016-01-18T19:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Specifying a date range in field extraction window</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228335#M67480</link>
      <description>&lt;P&gt;What version of Splunk you're using??&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 20:38:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228335#M67480</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-01-18T20:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Specifying a date range in field extraction window</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228336#M67481</link>
      <description>&lt;P&gt;Splunk Enterprise Server 6.3.2&lt;/P&gt;

&lt;P&gt;The filter they give only goes back 1 week, I need to go back months.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 20:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228336#M67481</guid>
      <dc:creator>Spiere</dc:creator>
      <dc:date>2016-01-18T20:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Specifying a date range in field extraction window</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228337#M67482</link>
      <description>&lt;P&gt;If I perform a search and drill my way down to a particular time frame (In my currently open test on my laptop - " 2 events (12/15/15 1:00:00.000 AM to 12/15/15 2:00:00.000 AM) "), then click "Extract New Fields" from the bottom of the fields list on the left, it takes me to a "Extract Fields, Select Sample" page with only the two events I had selected showing.&lt;/P&gt;

&lt;P&gt;I can change my timeframe in search and repeat clicking the "Extract New Fields" with various numbers of events showing, but always that count matches what I had displayed in the search before.&lt;/P&gt;

&lt;P&gt;Does it not do this for you?  Are you getting to the field extractor via some other method?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 21:03:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228337#M67482</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-01-18T21:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Specifying a date range in field extraction window</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228338#M67483</link>
      <description>&lt;P&gt;Ah that did it.  I was manually navigating to it through the settings menu.  Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 18:20:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228338#M67483</guid>
      <dc:creator>Spiere</dc:creator>
      <dc:date>2016-01-19T18:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Specifying a date range in field extraction window</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228339#M67484</link>
      <description>&lt;P&gt;If you post that as an answer ill accept it.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 18:21:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228339#M67484</guid>
      <dc:creator>Spiere</dc:creator>
      <dc:date>2016-01-19T18:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: Specifying a date range in field extraction window</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228340#M67485</link>
      <description>&lt;P&gt;Done, thanks, and glad I could help!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 18:26:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Specifying-a-date-range-in-field-extraction-window/m-p/228340#M67485</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-01-19T18:26:57Z</dc:date>
    </item>
  </channel>
</rss>

