Splunk Search

Datamodel summariesonly

jadengoho
Builder

Why are  we seeing logs from year ago even we use sumarriesonly=t

| tstats summariesonly=t earliest(_time) as EarliestDateEpoch from datamodel=Authentication where earliest=-8mon
| eval EarliestDate=strftime(EarliestDateEpoch,"%m-%d-%Y")

 

Even the summary range = 1month, i just want to get the earliest date of the summaries.

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Cloud Platform | Customer Change Announcement: Email Notification Will Be Available ...

The Notification Team is migrating our email service provider since currently there’s no support ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...