Splunk Search

Inconsistent search result

PeterEccles
Explorer

I have been using the range picker for a long time to run a search against data ingested the previous day. I normally use the Date Range picker and select the date between yesterday’s date 00:00 and yesterday’s date 24:00. This has worked fine for me. I was told that I can just use the "Yesterday" preset (or add earliest=-d@d latest=@d to the query). I know its obvious, but I missed it.

I get different results if I use the preset "Yesterday" against what I have been doing with the date picker. This is not a minor difference.

Can anyone think why this might be happening?

Thank you!

0 Karma
1 Solution

PeterEccles
Explorer

Please ignore this.  I made a mistake 😞

View solution in original post

0 Karma

annbrown
New Member

It's okay, it happens. Meanwhile, I would like to say that I'm a dissertation literature review writer.

0 Karma

PeterEccles
Explorer

Please ignore this.  I made a mistake 😞

0 Karma

to4kawa
Ultra Champion

My sample query's result is following(Today is 12/24): 

yesterday: 57,233 events (12/22/20 12:00:00.000 AM to 12/23/20 12:00:00.000 AM)  12/23 00:00:00~24:00:00:123,998 events (12/23/20 12:00:00.000 AM to 12/24/20 12:00:00.000 AM)

I think @d is not the intended date.

0 Karma

PeterEccles
Explorer

-d@d is 100% coming back with the correct date (yesterday)  it just not the same number of results as when I pick the date from the ranger picker. 

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...