Dashboards & Visualizations

Time Range question

palisetty
Communicator

I am new to Splunk, what is meant by "-1d@d+12h" in the time-range? Please explain

Tags (1)
0 Karma
1 Solution

vnravikumar
Champion

Hi

It represents yesterday at 12 pm. -1d@d - today -1(yesterday) @d+12h - 12 pm

View solution in original post

0 Karma

palisetty
Communicator

Ravi -24h@h means?
@h is the current hour.
-24h means 24 hours of yesterday? I so, when is the start time?
Please correct me.

0 Karma

vnravikumar
Champion

current time(hour) - 24 hours

0 Karma

palisetty
Communicator

Thank you so much for your effort.
I entered +h@h and it is displaying at 3:30. The current time is 2:55. If @ is rounding off, it should round off to 4:00 right

0 Karma

vnravikumar
Champion

you can check it by entering in the time range

Sample url

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Search Reference manual explains time modifiers. See https://docs.splunk.com/Documentation/Splunk/7.3.3/SearchReference/SearchTimeModifiers. In this example, the time range starts at noon yesterday (one day ago at 0:00 ("-1d@d") plus twelve hours ("+12h")).

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnravikumar
Champion

Hi

It represents yesterday at 12 pm. -1d@d - today -1(yesterday) @d+12h - 12 pm

0 Karma

palisetty
Communicator

Thank You. You mean, 1d@d = today.
-1d@d=yesterday?

0 Karma

vnravikumar
Champion

@d today, -1d@d=yesterday

0 Karma

palisetty
Communicator

1d@d means? Please don't mind about asking silly questions. I am trying to make sure I get it.

0 Karma

vnravikumar
Champion

1d@d - Invalid. If you prefix + +1d@d represents next day

0 Karma

palisetty
Communicator

Perfect. Thank You

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...