Splunk Search

Data Model custom timerange check

vn_g
Path Finder

How to pass earliest and latest values to a data model search?  Example if I select a time range picker of last 30 mins but still give earliest and latest in the normal search of last 24 hours, then earliest and latest parameters take precedence and works in a normal search. How to implement the same with datamodel query?

 

Labels (1)
0 Karma

vn_g
Path Finder

1.I have time attribute added as required.

2. I have set the Summarization Period to run once in every 5 mins. (*/5 * * * *) and the old summaries clean up is default 30 mins.

3. Added summary range earliest time to 91 days.

4. Adding summariesonly = true, doesnt give any results --> for 1 hour as well.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @vn_g ,

the first question is what's the update frequency of your Data Model?

if it's more than 30 minutes , you cannot run a search on a Data Model in tha last 30 minutes.

Anyway, to search only on the Data Model without applying also the index events, you have to add to your searches summariesonly = True

Ciao.

Giuseppe

0 Karma

vn_g
Path Finder

I found a way to add earliest and latest using tstats from datamodel, but the values are not matching when querying from tstats and direct index? What could be the fix? I set the frequency to run once in every 5 minutes and earliest time to 91 days. And max summarization search time to 1 hour.

0 Karma

vn_g
Path Finder

1.I have time attribute added as required.

2. I have set the Summarization Period to run once in every 5 mins. (*/5 * * * *) and the old summaries clean up is default 30 mins.

3. Added summary range earliest time to 91 days.

4. Adding summariesonly = true, doesnt give any results --> for 1 hour as well.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...