Splunk Search

How to monitor log time from 22.00 to 8.00?

hiepdv4
New Member

Dear all.

Please support me about monitor and statistics log from 22.00 to 8.00

Thanks

0 Karma
1 Solution

HiroshiSatoh
Champion

It can be extracted under the following conditions. I think it should be macrosized for a long time.

(your search) (date_hour=22 OR date_hour=23 OR date_hour=0 OR date_hour=1 OR date_hour=2 OR date_hour=3 OR date_hour=4 OR date_hour=5 OR date_hour=6 OR date_hour=7 OR date_hour=8)

View solution in original post

0 Karma

HiroshiSatoh
Champion

It can be extracted under the following conditions. I think it should be macrosized for a long time.

(your search) (date_hour=22 OR date_hour=23 OR date_hour=0 OR date_hour=1 OR date_hour=2 OR date_hour=3 OR date_hour=4 OR date_hour=5 OR date_hour=6 OR date_hour=7 OR date_hour=8)
0 Karma

hiepdv4
New Member

Dear Hiroshi-san

Thanks for support.

Regards

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Would you please provide more information about what you are trying to do and how you are trying to do it?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...