Splunk Search

Inconsistent search result

PeterEccles
Explorer

I have been using the range picker for a long time to run a search against data ingested the previous day. I normally use the Date Range picker and select the date between yesterday’s date 00:00 and yesterday’s date 24:00. This has worked fine for me. I was told that I can just use the "Yesterday" preset (or add earliest=-d@d latest=@d to the query). I know its obvious, but I missed it.

I get different results if I use the preset "Yesterday" against what I have been doing with the date picker. This is not a minor difference.

Can anyone think why this might be happening?

Thank you!

0 Karma
1 Solution

PeterEccles
Explorer

Please ignore this.  I made a mistake 😞

View solution in original post

0 Karma

annbrown
New Member

It's okay, it happens. Meanwhile, I would like to say that I'm a dissertation literature review writer.

0 Karma

PeterEccles
Explorer

Please ignore this.  I made a mistake 😞

0 Karma

to4kawa
Ultra Champion

My sample query's result is following(Today is 12/24): 

yesterday: 57,233 events (12/22/20 12:00:00.000 AM to 12/23/20 12:00:00.000 AM)  12/23 00:00:00~24:00:00:123,998 events (12/23/20 12:00:00.000 AM to 12/24/20 12:00:00.000 AM)

I think @d is not the intended date.

0 Karma

PeterEccles
Explorer

-d@d is 100% coming back with the correct date (yesterday)  it just not the same number of results as when I pick the date from the ranger picker. 

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...