Splunk Enterprise

Drill-down Search Earliest Latest Offset

Splunk_Fabi
Observer

When I edit a correlation search, I want to configure the time of the drill-down search. 

If I put "1h" in the form "Earliest Offset", it inputs the unix time stamp in milliseconds. Splunk expects the unix time stamp in seconds. Is there a workaround for this issue?

Splunk_Fabi_1-1734358080924.png

-> 

Splunk_Fabi_2-1734358160494.png


Correct would be:

Splunk_Fabi_3-1734358215056.png

 

 

Labels (2)
0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

@Splunk_Fabi Hello, which version of ES are you using? I have seen a similar bug in 7.3.2 (a fix might be on the future roadmap). If you are on 7.3.2, please file a ticket with Splunk Support to expedite the issue.

 

 

 

If this Helps, Please Upvote.

 

 

If this helps, Upvote!!!!
Together we make the Splunk Community stronger 
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...