earliest=-0@d latest=now) OR (earliest=-7d@d latest=-6d@d) -- This is giving me the comparison of Today vs -7 days.
Instead, Dynamically I need to choose the date (whatever I want) and other should automatically show the -7d. Could someone please help with this.
Hi @Prathyusha891,
did you never explored the timewrap command (https://docs.splunk.com/Documentation/SCS/current/SearchReference/TimewrapCommandOverview 😞 it gives you the same results without the need to calculate times.
Ciao.
Giuseppe