Splunk Search

How to get the earliest and latest for the last full hour

damucka
Builder

Hello,

How would I set the earliest and latest to the last full hour?
Example:
current time 5:19 pm
I want earliest=4pm and latest=5pm

Kind regards,
Kamil

1 Solution

woodcock
Esteemed Legend

In the SPL you can use earliest=-1h@h latest=@h and you can use the Advanced area of the Time picker you can use the same values.

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI damucka
try earliest=-h@h latest=@h, anyway you can also use the time picker to find the correct time intervals.

Ciao.
Giuseppe

0 Karma

woodcock
Esteemed Legend

In the SPL you can use earliest=-1h@h latest=@h and you can use the Advanced area of the Time picker you can use the same values.

0 Karma
Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...