Getting Data In

what format should timestamp be in for starttime?

HattrickNZ
Motivator

Regarding starttime from the docs

starttime starttime=<timestamp> Search from the specified date and time to the present (inclusive of the specified time).

What format should `` be in?

I have got this working starttime= 04/27/2015:00:00:00, that is mm/dd/yyyy, but I am seeing strange results, possibly duplicates in data. Can anyone advise?

For my reference this is in relation to this Q

0 Karma

richgalloway
SplunkTrust
SplunkTrust

starttime is deprecated and should be avoided. Use earliest, instead. That said, the timestamp format you used is correct. If you want to try a different format, use timeformat (another deprecated command).

I suggest you post a separate question with your search query and sample data so we can help resolve your "strange results".

---
If this reply helps you, Karma would be appreciated.
0 Karma

HattrickNZ
Motivator

I have done in the past and this was the solution then. Can I control earliest and latest date using fixed dates ? I will post it again, shall i?

0 Karma

HattrickNZ
Motivator
0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...