Dashboards & Visualizations

Time Range question

palisetty
Communicator

I am new to Splunk, what is meant by "-1d@d+12h" in the time-range? Please explain

Tags (1)
0 Karma
1 Solution

vnravikumar
Champion

Hi

It represents yesterday at 12 pm. -1d@d - today -1(yesterday) @d+12h - 12 pm

View solution in original post

0 Karma

palisetty
Communicator

Ravi -24h@h means?
@h is the current hour.
-24h means 24 hours of yesterday? I so, when is the start time?
Please correct me.

0 Karma

vnravikumar
Champion

current time(hour) - 24 hours

0 Karma

palisetty
Communicator

Thank you so much for your effort.
I entered +h@h and it is displaying at 3:30. The current time is 2:55. If @ is rounding off, it should round off to 4:00 right

0 Karma

vnravikumar
Champion

you can check it by entering in the time range

Sample url

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Search Reference manual explains time modifiers. See https://docs.splunk.com/Documentation/Splunk/7.3.3/SearchReference/SearchTimeModifiers. In this example, the time range starts at noon yesterday (one day ago at 0:00 ("-1d@d") plus twelve hours ("+12h")).

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnravikumar
Champion

Hi

It represents yesterday at 12 pm. -1d@d - today -1(yesterday) @d+12h - 12 pm

0 Karma

palisetty
Communicator

Thank You. You mean, 1d@d = today.
-1d@d=yesterday?

0 Karma

vnravikumar
Champion

@d today, -1d@d=yesterday

0 Karma

palisetty
Communicator

1d@d means? Please don't mind about asking silly questions. I am trying to make sure I get it.

0 Karma

vnravikumar
Champion

1d@d - Invalid. If you prefix + +1d@d represents next day

0 Karma

palisetty
Communicator

Perfect. Thank You

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...