Splunk Search

Dynamic query to get the result in specific timeframe for any days

anirban_nag
Explorer

I have a specific timeframe say from 1AM to 2AM. In this 1 hour I want to see all the failures from my log. But I want to see this timeframe failures not for only today but for N no of days. This N will be specified from the Date Range dropdown.

Bouns point if I can get the result for each day in a column chart side by side.

Tags (2)
0 Karma
1 Solution

inventsekar
SplunkTrust
SplunkTrust

we can use date_hour and solve this specific timeframe issue.
Try this one -

 index=main sourcetype=yourSourcetype earliest=-31d latest=-1d (date_hour > 1 OR date_hour < 2) | chart count(Failure) by sourcetype over host
thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

View solution in original post

inventsekar
SplunkTrust
SplunkTrust

we can use date_hour and solve this specific timeframe issue.
Try this one -

 index=main sourcetype=yourSourcetype earliest=-31d latest=-1d (date_hour > 1 OR date_hour < 2) | chart count(Failure) by sourcetype over host
thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...