Splunk Search

Can't seem to understand relative_time

sfghjkl
New Member

Hi,

I am working my way through some of the splunk courses. I am currently on "working with time".

In one of the videos the following command is used to find all results within the past day, rounding down.

"| eval yesterday = relative_time(now(),"1d@h")".

However when I attempt this command myself, it simply prints the "yesterday" value however it uses the time specified in my time picker, not in the actual command.

I was under the impression that any time specified within a command would automatically overwrite the time picker.

Was I mistaken in this? Or am I perhaps using the command incorrectly?

Any help would be greatly appreicated.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The eval command merely assigns a value to a field (variable).  It has no effect on the time picker.

What *does* override the time picker are the earliest and latest options in the search command.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...