Hello I need one help please.
I am creating a report to show data for last week i.e. 00:00hrs from 08/25/2025 to 00:00hrs on 01/09/2025.
Shall I use time modifier as below-
<earliest>-7d@d</earliest>
<latest>@d</latest>
Please advise.
thanks
Hi I used below and it worked-
<earliest>-7d@d</earliest>
<latest>@d</latest>
I got the answer. Please ignore that.
When you found answer, please add it here. So other can get it too when they have a same issue.
Here is link to time modifier section on help.splunk.com https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.0/specify-time-ranges/specify-t...
Thank you for the response. It helps.
Hi I used below and it worked-
<earliest>-7d@d</earliest>
<latest>@d</latest>