Getting Data In

Can we set a time range from today 00:00:00 AM to real time now?

chrbar01
Explorer

Hello,

I would like to set a search for the 24H of the current day: a time range from today 00:00:00 AM to real time now?
Is it possible?
If yes, could you explain to me how to do that?

Thanks,
Chris

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Use earliest=@d latest=now.

View solution in original post

somesoni2
Revered Legend

Use earliest=@d latest=now.

cmerriman
Super Champion

in the Advanced tab on the Time Range Picker, you could put "@d" in earliest and "now" in latest, would that work?

chrbar01
Explorer

Thanks for your help 🙂

I'd like to set this range in real time.
I've found a solution with the values "rt-1@d" in earliest and "rt" in latest, inside the Advanced tab of the Time Range Picker.
It works, but if I enter the same value into the Search command line (earliest="rt-1@d" latest="rt"), I obtain the error: Invalid value "rt-1@d" for time term 'earliest'.
Do you know why?

0 Karma

somesoni2
Revered Legend

The realtime time ranges are not designed to be applied inline in search. Read this for more details

https://docs.splunk.com/Documentation/Splunk/6.5.0/Search/Specifyrealtimewindowsinyoursearch#Real-ti... (3rd para)

chrbar01
Explorer

Ok, thanks a lot.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...