Dashboards & Visualizations

9:37 30m@d

palisetty
Communicator

@gcusello

9:37 -30m@h
Sorry for asking this again. As far as I understand, I will tell you kindly correct me.
@h is current hour, which goes to 9. -30m which is 30 minutes before current hour, so it will be 8:30 - 8:59.


9:37 -30m@d
@d is current day at 0:00 hours. so -30m would be yesterday 23:30 to 23:59.

Tags (1)
0 Karma

pramit46
Contributor

If you run the following search at 09:37 AM:
index=_internal earliest=-1h@h lastest=now, then earliest time will be: 08:00 AM and latest time will be: 09:37 AM

If you run the following search at 09:37 AM:
index=_internal earliest=-1h lastest=now, then earliest time will be: 08:37 AM and latest time will be: 09:37 AM

0 Karma
Get Updates on the Splunk Community!

New Case Study: How LSU’s Student-Powered SOCs and Splunk Are Shaping the Future of ...

Louisiana State University (LSU) is shaping the next generation of cybersecurity professionals through its ...

Splunk and Fraud

Join us on November 13 at 11 am PT / 2 pm ET!Join us for an insightful webinar where we delve into the ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...