Splunk Search

How do I search with a self adjusting time?

fmerrow
New Member

So on the GUI I have been looking at the various time pickers . . . specifically "Date & Time" and "Advanced".

I see advanced in particular can do limited arithmetic (@d-1m), etc.

Basically, what I am hoping for, is for the user to cut a date/time out of a log, then come to say "Advanced" and do the following:

In Earliest have something prepopulated like lastest-2m and in Latest paste the copied value.

Now I realize the same could be accomplished with "Date&Time", except the date needs to be pasted twice and then earliest needs to be played with by hand.

I am hoping to get this down to a single paste and no hand editing . . . just paste and search.

Is that possible?

Frank

0 Karma

woodcock
Esteemed Legend
0 Karma

fmerrow
New Member

Interesting . . . I'll check it out. Thank you.

0 Karma
Get Updates on the Splunk Community!

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...