Splunk Search

How to create a complex WHERE condition?

jip31
Motivator

Hi

I have to create a complex SPL command (for me ;-))
In this command, I want to search a specific word which start by W10P02xx in a log file and with a date which is previous to month -2 (26 January for today)
I think we have to use a WHERE condition but after???
Is it possible ith SPL command?
Thanks a lot

0 Karma
1 Solution

tiagofbmm
Influencer

Hey

The first part you can you where yourfield like W10P02xx%

The month part, you create a variable last_time with the function relative_time and get 2 months backwards. Then use it to filter your results with an AND

View solution in original post

0 Karma

jip31
Motivator

thanks tiago you are champion 😉

0 Karma

tiagofbmm
Influencer

Please don't forget to accept and upvote the answer

0 Karma

tiagofbmm
Influencer
Yoursearch| eval time_threshold=relative_time(now(), "-2M@d") | where yourfield like "W10P02xx%" AND _time>time_threshold
0 Karma

tiagofbmm
Influencer

You accepted your own answer. Please unaccept yours and accept my answer to the question

0 Karma

jip31
Motivator

thanks tiago but im not sure to succeed ...........

0 Karma

tiagofbmm
Influencer

Hey

The first part you can you where yourfield like W10P02xx%

The month part, you create a variable last_time with the function relative_time and get 2 months backwards. Then use it to filter your results with an AND

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...