Splunk Search

How to display the exact date from time modifiers?


I would like to know how to display the exact date of the time modifiers which are specified in the earliest and latest time range.
Eg: earliest=-1q@q latest=@q

We know that this is nothing but the last quarter details, which is earliest =01-01-2019 and latest=31-03-2019.
I am using the time modifier in my query and I want to display the above format date along with my other panels in my dashboard.
This may change according to each quarter/year we select from input.

I am using this in a case condition,

        <eval token="growth_title2">case($result.time_period$=="earliest=-1q@q latest=@q","xxxx", $result.time_period$=="earliest=-1y@y latest=@y", "yyyy")</eval>

The place xxxx and yyyy needed the logic to display the earliest & latest time in date format

Could anyone please help me to display time which is mentioned in time modifier as date format.

0 Karma

Esteemed Legend

I have no idea what you mean by this. More explanation is required. Perhaps show examples.

0 Karma


Hi @akarivaratharaj,

Can you please try this:

<eval token="growth_title2">strftime(relative_time(now(), earliest), "%d-%m-%Y")." to ".strftime(relative_time(now(), latest), "%d-%m-%Y")</eval>

For reference:


I modified this for my requirements. Works like a charm.
Thanks and God bless,

0 Karma


@genesiusj Glad to hear it.


0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...