Splunk Search

How can I search events occured in last one hour

New Member

Hi,

Is there any command for filtering out the search results that occured in last 24 hrs.

Please help.

Tags (4)
0 Karma

Legend

You can either use the timerange picker in the web GUI, or you can use time modifiers directly in your search, like this:

... earliest=-1d

http://docs.splunk.com/Documentation/Splunk/6.0.3/SearchReference/SearchTimeModifiers

Legend

Please read docs and apply a suitable one. This is no place where we solve all your problems for you, rather we help you solve problems.

0 Karma

SplunkTrust
SplunkTrust
0 Karma

New Member

I m on 5.0.3, Please provide suitable one, from your solution it is saying invalid earliest command

0 Karma