Splunk Search

Search Time Range

dellytaniasetia
Explorer

Hi,

I have a simple question, what is the difference between earliest=-15m with earliest=-15m@s?

I could not find any diff when run my search. Any help is appreciated. Thanks

Tags (2)
0 Karma

acharlieh
Influencer

It is possible that you don't see a difference because you may not have any data that would be different. The relative time modifiers is discussed in the documents here: https://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/SearchTimeModifiers#How_to_specif...

But for your specific question... Let's say you're running a search and it is right now to the sub-second exactly: 12:51:39.135

earliest=-15m would mean the earliest time for your time range is exactly 15 minutes ago, or 12:36:39.135

earliest=-15m@s means take the current time, subtract 15 minutes, and then round down to the nearest second, or in other words: 12:36:39.000

Unless you're dealing with high volumes of data that comes from devices that log down to subsecond precision it's unlikely that you would see differences between these two examples. But relative time modifiers locking down in general is a pretty handy thing to be familiar with.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...