- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
time modifiers
Sukhmeet
New Member
2 weeks ago
Here is the situation
Search web security appliance data (index=network sourcetype=cisco_wsa_squid) for non-business
activity, i.e., usage values other than Business (usage!=Business) during the previous business week.
And here is query i got for it
index=network sourcetype=cisco_wsa_squid (usage!=Business)
earliest=-7d@w1 latest=@w6.
Could someone explain in latest why is it @w6 and not -7d@w6, @w6 will not include current week's data ?
#timemodiefiers
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ITWhisperer

SplunkTrust
2 weeks ago
"@w6" aligns to the beginning of the previous Saturday (which is not in the current week!). Try "@w6+1w"
