Getting Data In

Can we set a time range from today 00:00:00 AM to real time now?

chrbar01
Explorer

Hello,

I would like to set a search for the 24H of the current day: a time range from today 00:00:00 AM to real time now?
Is it possible?
If yes, could you explain to me how to do that?

Thanks,
Chris

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Use earliest=@d latest=now.

View solution in original post

somesoni2
Revered Legend

Use earliest=@d latest=now.

cmerriman
Super Champion

in the Advanced tab on the Time Range Picker, you could put "@d" in earliest and "now" in latest, would that work?

chrbar01
Explorer

Thanks for your help 🙂

I'd like to set this range in real time.
I've found a solution with the values "rt-1@d" in earliest and "rt" in latest, inside the Advanced tab of the Time Range Picker.
It works, but if I enter the same value into the Search command line (earliest="rt-1@d" latest="rt"), I obtain the error: Invalid value "rt-1@d" for time term 'earliest'.
Do you know why?

0 Karma

somesoni2
Revered Legend

The realtime time ranges are not designed to be applied inline in search. Read this for more details

https://docs.splunk.com/Documentation/Splunk/6.5.0/Search/Specifyrealtimewindowsinyoursearch#Real-ti... (3rd para)

chrbar01
Explorer

Ok, thanks a lot.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...