Getting Data In

Can we set a time range from today 00:00:00 AM to real time now?

chrbar01
Explorer

Hello,

I would like to set a search for the 24H of the current day: a time range from today 00:00:00 AM to real time now?
Is it possible?
If yes, could you explain to me how to do that?

Thanks,
Chris

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Use earliest=@d latest=now.

View solution in original post

somesoni2
Revered Legend

Use earliest=@d latest=now.

cmerriman
Super Champion

in the Advanced tab on the Time Range Picker, you could put "@d" in earliest and "now" in latest, would that work?

chrbar01
Explorer

Thanks for your help 🙂

I'd like to set this range in real time.
I've found a solution with the values "rt-1@d" in earliest and "rt" in latest, inside the Advanced tab of the Time Range Picker.
It works, but if I enter the same value into the Search command line (earliest="rt-1@d" latest="rt"), I obtain the error: Invalid value "rt-1@d" for time term 'earliest'.
Do you know why?

0 Karma

somesoni2
Revered Legend

The realtime time ranges are not designed to be applied inline in search. Read this for more details

https://docs.splunk.com/Documentation/Splunk/6.5.0/Search/Specifyrealtimewindowsinyoursearch#Real-ti... (3rd para)

chrbar01
Explorer

Ok, thanks a lot.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...