Splunk Search

How to use the time picker $earliest$ and $latest$ time set by the user in my custom Python search command?



I'm trying to use the $earliest$ and $latest$ time set by the user time picker in my custom search command. I'm using the Python SDK 1.5.0 for this.
I found the input_header field of the SearchCommand class, but it doesn't contain the information I'm looking for.
Is this information available to custom search commands in any way? I'd like to have something like the results produced by the addinfo command.

Thanks for ideas!

0 Karma



Here is an example of how you get to these variables:

search_results = self.search_results_info
earliest = int(search_results.search_et)
latest = int(search_results.search_lt)

Hope this helps!

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!