Splunk Search

Adding and defining the value for a new Search Field.

Substance82
Path Finder

How do I add a  new field and set the value to seven days ago from the current date, snapped to the
beginning of the current date? I know the date syntax should be "earliest=-7d@d", but am unsure if I should use the eval command to add the field and the specific syntax. Thanks. 

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

eval is the command to use to add a new field to an event.  Use the relative_time function to help set the value.

| eval newField = relative_time(now(), "-7d@d")

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

eval is the command to use to add a new field to an event.  Use the relative_time function to help set the value.

| eval newField = relative_time(now(), "-7d@d")

 

---
If this reply helps you, Karma would be appreciated.

Substance82
Path Finder

Thanks a million!

0 Karma
Get Updates on the Splunk Community!

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...