Splunk Search

Can't seem to understand relative_time

sfghjkl
New Member

Hi,

I am working my way through some of the splunk courses. I am currently on "working with time".

In one of the videos the following command is used to find all results within the past day, rounding down.

"| eval yesterday = relative_time(now(),"1d@h")".

However when I attempt this command myself, it simply prints the "yesterday" value however it uses the time specified in my time picker, not in the actual command.

I was under the impression that any time specified within a command would automatically overwrite the time picker.

Was I mistaken in this? Or am I perhaps using the command incorrectly?

Any help would be greatly appreicated.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The eval command merely assigns a value to a field (variable).  It has no effect on the time picker.

What *does* override the time picker are the earliest and latest options in the search command.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...