i'm using Splunk java sdk to get search result. i want to setup timestamp for my search.
Args oneshotSearchArgs = new Args();
oneshotSearchArgs.put("earliest_time", "2019-02-19T12:00:00.000-07:00");
oneshotSearchArgs.put("latest_time", "2019-02-20T12:00:00.000-07:00");
String oneshotSearchQuery ="search index=app | head 2";
Instead giving date manually, i want to give
earliest_time --> 2 days
latest_time --> now
How can i do it?
@Hunterzz
You can specify Splunk time modifier in oneshot arguments. Please check below link for Splunk time modifier example.
Please check To run a basic oneshot search and display results
in http://dev.splunk.com/view/java-sdk/SP-CAAAEHQ .