Reporting

How to specify format for absolute time in a report?

llapd2001
Explorer

Hi,

I am new to splunk and i have a minor problem.

When i created a report at the start time(dispatch.earliest_time) i would like to use an absolute time(like a date and time) but i don't know the correct format.

This is the format in the documentation but it is not working: 10/19/2009:0:0:0 I got this error: Encountered the following error while trying to update: In handler 'savedsearch': Cannot parse time argument 'dispatch.earliest_time': '2012-06-20T16:27:43.000-07:00'

Can someone point me to the correct format?

Thanks, laszlo

Tags (3)
0 Karma

alexantao
Path Finder

I got on this problem now.
The last version of Splunk still does not provide an easy way to do this.

You can specify the absolute time in the "unix seconds" format. You can use a convertion tool as said before ou create a report from search web, specify the times you want and then use it on you own report or modify the saved one to you needs...

0 Karma

somesoni2
Revered Legend

Use the epoch time to provide absolute time e.g. epoch equivalent for StartTime and FinishTime values from Splunk Web UI (use http://www.epochconverter.com/ or similar sites to get that.)

0 Karma

llapd2001
Explorer

I dont have access to the cli.

So i think then this is it...no absolute time in web.

thanks,
laszlo

0 Karma

strive
Influencer

I dont think that you can specify absolute time in Web. If you see the time specifiers below the text box, they are all relative. The link learn more also points to relative time.
/en-US/help?location=learnmore.manager.relativetime

Dont you have option to edit the savedsearches.conf?

llapd2001
Explorer

I cannot upload a picture here in the forum.

I uploded one here:
https://drive.google.com/file/d/0B-UcVhaZZeNudGRPTkxfLTNzODg/edit?usp=sharing

Please take a look.
So i am just using the web interface to create this report and never used format. dispatch.time_format

thanks
laszlo

0 Karma

strive
Influencer

If you use absolute time then you should also specify the format. dispatch.time_format to format the value

Have you used dispatch.time_format.

Can you post the configurations here

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...