Splunk Search

Defining search timeframe from midnight to now

beaumaris
Communicator

We have situations where we just want to show what happened "today", which is defined as from Midnight to now. That's easy to say in English, and it's easy to define latest=now, but I am having trouble figuring out what to specify as the 'earliest' value to get Splunk to understand midnight.

Tags (2)
1 Solution

southeringtonp
Motivator

Midnight is just zero hours, relative to the current day, so you can use:

 earliest=-0h@d

or just:

earliest=@d

You should also have Today available as an option in the TimeRangePicker.

View solution in original post

southeringtonp
Motivator

Midnight is just zero hours, relative to the current day, so you can use:

 earliest=-0h@d

or just:

earliest=@d

You should also have Today available as an option in the TimeRangePicker.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...