I looked at the documentation here: http://www.splunk.com/base/Documentation/4.1.1/SearchReference/CLIsearchsyntax
And it states to use either the "latest_time" or the "earliest_time" for time, and for either of these I can use the Relative Time Modifiers found here: http://www.splunk.com/base/Documentation/4.1.1/User/ChangeTheTimeRangeOfYourSearch
The "earliest_time" appears to start from the current time and go backwards, so I'm using it.
I have run the following for the earliest_time:
./splunk search 'host="was01" earliest_time=-15m@s'
The results retrieved are NOT within the last 15 minutes (ran query @ 15:38):
[6/4/10 15:38:31:623 CDT]
[6/4/10 15:37:36:051 CDT]
Any ideas on why it is only going back about 1 minute instead of 15 minutes like my query is intended to?
What am I doing wrong?