Splunk Search

How to change the time range for a subsearch?



I am creating a search that will take date range from datetime field that I have created above. However, inside that search I am using a subsearch which needs last week's avg data. To get that, I have to fetch last week data and make an average for it.

How do I apply last week's time range for the subsearch?

Kindly assist.

Tags (2)
0 Karma


You can set the inner time range using explicit earliest and latest:

outer search ... [search earliest=-w latest=now inner search ...] ...

That will override the outer time range for the inner search.