If the event time (_time) is greater than the current time (now) rounded to the nearest day (relative_time(now, "-0d@d")) then do something.
See relative_time and now() documentation
If helps, "-0d@d" and "@d" are equivalent. See the time modifiers page for more information.
Thanks,
J
Hi @Deepali529 - Did one of the answers below help solve your question? If yes, please click on "Accept" below the best answer to resolve this post. If not, please comment with feedback. Thank you!
_time
represents the time the event occurred.
relative_time()
: takes an time (epoch), as the first argument and a relative time difference, as the second argument and returns the epochtime value of difference from time. In you example, it will return "-0d@d" which is same as start of day = TODAY() at 12:00:00.
http://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/CommonEvalFunctions
If the event time (_time) is greater than the current time (now) rounded to the nearest day (relative_time(now, "-0d@d")) then do something.
See relative_time and now() documentation
If helps, "-0d@d" and "@d" are equivalent. See the time modifiers page for more information.
Thanks,
J