Splunk Search

How to search for events with latest time down to the millisecond?

vpao
Engager

Hi,

My Splunk indexes event time down to the millisecond (e.g., 01/14/2016 23:59:59.326 AM). I know this can find events down to the second:

index=index1 sourcetype=sourcetype1 earliest=01/08/2016:00:00:00 latest=01/14/2016:23:59:59

Is there a way to find events down to the millisecond?

0 Karma
1 Solution

somesoni2
Revered Legend

You can use the subsearch method to achieve the same. See this run anywhere example

index=_internal   [| gentimes start=-1 | eval earliest=strptime("08/01/2016 10:53:54.987","%m/%d/%Y %H:%M:%S.%N") | table earliest] [| gentimes start=-1 | eval latest=strptime("08/01/2016 10:53:54.997","%m/%d/%Y %H:%M:%S.%N") | table latest ]| head 100

View solution in original post

0 Karma

somesoni2
Revered Legend

You can use the subsearch method to achieve the same. See this run anywhere example

index=_internal   [| gentimes start=-1 | eval earliest=strptime("08/01/2016 10:53:54.987","%m/%d/%Y %H:%M:%S.%N") | table earliest] [| gentimes start=-1 | eval latest=strptime("08/01/2016 10:53:54.997","%m/%d/%Y %H:%M:%S.%N") | table latest ]| head 100
0 Karma

sundareshr
Legend

This will include all event between 01/08 and 01/14

index=index1 sourcetype=sourcetype1 earliest=01/08/2016:00:00:00 latest=01/15/2016:00:00:00
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...