Splunk Search

How do I search with a self adjusting time?

fmerrow
New Member

So on the GUI I have been looking at the various time pickers . . . specifically "Date & Time" and "Advanced".

I see advanced in particular can do limited arithmetic (@d-1m), etc.

Basically, what I am hoping for, is for the user to cut a date/time out of a log, then come to say "Advanced" and do the following:

In Earliest have something prepopulated like lastest-2m and in Latest paste the copied value.

Now I realize the same could be accomplished with "Date&Time", except the date needs to be pasted twice and then earliest needs to be played with by hand.

I am hoping to get this down to a single paste and no hand editing . . . just paste and search.

Is that possible?

Frank

0 Karma

woodcock
Esteemed Legend
0 Karma

fmerrow
New Member

Interesting . . . I'll check it out. Thank you.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...