Splunk Search

Log searching Splunk

av_
Path Finder

I am searching some logs in an application for the last 24 hours (or any time range the user has selected). Is it possible to search the same logs in another application for the next day? 

Eg: if the user has selected the time range as last one hour, can I see the trajectory of those logs over a period of next day?

0 Karma

bowesmana
SplunkTrust
SplunkTrust

When you say "in another application" what do you mean

The predict command can be used to predict future trends

https://docs.splunk.com/Documentation/SplunkCloud/9.1.2312/SearchReference/Predict

 

 

0 Karma

marnall
Motivator

As in running the same search that another user has previously run, but in a different time period?

0 Karma

av_
Path Finder

@marnall @Not really, it’s like if I’m running the search for last 24 hrs, I’d like to see the data for now()+1d. 

0 Karma

marnall
Motivator

Probably the best thing for that, as bowesmana suggested, is the predict command, which would estimate what the data may look like in the future based on its behavior in the past. 

Unless you have data with timestamps in the future, you can't actually look at future data. now()+1d should be empty.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...