Dashboards & Visualizations

Time Range question

palisetty
Communicator

I am new to Splunk, what is meant by "-1d@d+12h" in the time-range? Please explain

Tags (1)
0 Karma
1 Solution

vnravikumar
Champion

Hi

It represents yesterday at 12 pm. -1d@d - today -1(yesterday) @d+12h - 12 pm

View solution in original post

0 Karma

palisetty
Communicator

Ravi -24h@h means?
@h is the current hour.
-24h means 24 hours of yesterday? I so, when is the start time?
Please correct me.

0 Karma

vnravikumar
Champion

current time(hour) - 24 hours

0 Karma

palisetty
Communicator

Thank you so much for your effort.
I entered +h@h and it is displaying at 3:30. The current time is 2:55. If @ is rounding off, it should round off to 4:00 right

0 Karma

vnravikumar
Champion

you can check it by entering in the time range

Sample url

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Search Reference manual explains time modifiers. See https://docs.splunk.com/Documentation/Splunk/7.3.3/SearchReference/SearchTimeModifiers. In this example, the time range starts at noon yesterday (one day ago at 0:00 ("-1d@d") plus twelve hours ("+12h")).

---
If this reply helps you, Karma would be appreciated.
0 Karma

vnravikumar
Champion

Hi

It represents yesterday at 12 pm. -1d@d - today -1(yesterday) @d+12h - 12 pm

0 Karma

palisetty
Communicator

Thank You. You mean, 1d@d = today.
-1d@d=yesterday?

0 Karma

vnravikumar
Champion

@d today, -1d@d=yesterday

0 Karma

palisetty
Communicator

1d@d means? Please don't mind about asking silly questions. I am trying to make sure I get it.

0 Karma

vnravikumar
Champion

1d@d - Invalid. If you prefix + +1d@d represents next day

0 Karma

palisetty
Communicator

Perfect. Thank You

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...