Splunk Search

How do I search with a self adjusting time?

fmerrow
New Member

So on the GUI I have been looking at the various time pickers . . . specifically "Date & Time" and "Advanced".

I see advanced in particular can do limited arithmetic (@d-1m), etc.

Basically, what I am hoping for, is for the user to cut a date/time out of a log, then come to say "Advanced" and do the following:

In Earliest have something prepopulated like lastest-2m and in Latest paste the copied value.

Now I realize the same could be accomplished with "Date&Time", except the date needs to be pasted twice and then earliest needs to be played with by hand.

I am hoping to get this down to a single paste and no hand editing . . . just paste and search.

Is that possible?

Frank

0 Karma

woodcock
Esteemed Legend
0 Karma

fmerrow
New Member

Interesting . . . I'll check it out. Thank you.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...