Splunk Search

Inconsistent search result

PeterEccles
Explorer

I have been using the range picker for a long time to run a search against data ingested the previous day. I normally use the Date Range picker and select the date between yesterday’s date 00:00 and yesterday’s date 24:00. This has worked fine for me. I was told that I can just use the "Yesterday" preset (or add earliest=-d@d latest=@d to the query). I know its obvious, but I missed it.

I get different results if I use the preset "Yesterday" against what I have been doing with the date picker. This is not a minor difference.

Can anyone think why this might be happening?

Thank you!

0 Karma
1 Solution

PeterEccles
Explorer

Please ignore this.  I made a mistake 😞

View solution in original post

0 Karma

annbrown
New Member

It's okay, it happens. Meanwhile, I would like to say that I'm a dissertation literature review writer.

0 Karma

PeterEccles
Explorer

Please ignore this.  I made a mistake 😞

0 Karma

to4kawa
Ultra Champion

My sample query's result is following(Today is 12/24): 

yesterday: 57,233 events (12/22/20 12:00:00.000 AM to 12/23/20 12:00:00.000 AM)  12/23 00:00:00~24:00:00:123,998 events (12/23/20 12:00:00.000 AM to 12/24/20 12:00:00.000 AM)

I think @d is not the intended date.

0 Karma

PeterEccles
Explorer

-d@d is 100% coming back with the correct date (yesterday)  it just not the same number of results as when I pick the date from the ranger picker. 

0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...