Splunk Dev

Why is relative time is search not working?

jip31
Motivator

hi

 

I use this relative time in my search

 

earliest=@d+7h latest=@d+19h 

 

 now I want the same slot time but one day ago (it means between 7h and 19h)

so i am doing this but it doenst works

 

earliest=-1d+7h latest=-1d+19h 

 

what is wrong please?

Tags (1)
0 Karma

johnhuang
Motivator

Keep in mind that =@d is a short way of expressing =-0d@d. As best practice, I recommend you use =-0d@d. 

 

earliest=-1d@d+7h latest=-1d@d+19h

 

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...