Splunk Search

Cut the time range

Cris
Explorer

In a search text is it possible to "cut" the time range selected in the "time range picker"?

Exsample:

Selecting "Yesterday" in the time range picker can I cut my search of two hours to obtain events that occurred between 0:00:00 AM and 10:00:00 PM on yesterday?

Selecting "Last 30 days" in the time range picker can I cut my search of two days to obtain events that occurred 28 days ago?

Thank you.

0 Karma

Drainy
Champion

a really simple way to define time would be to include earliest, latest or a combination of the two in your opening search statement.

E.g;

index=main earliest=-4d@d latest=-1d@d

would search back to between 4 days and 1 day ago.

EDIT:
Probably worth mentioning that you can define your own ranges for the time picker via times.conf too, have a look here;
http://docs.splunk.com/Documentation/Splunk/latest/admin/Timesconf

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...