Splunk Search

Search bar previous week

mrovira
Engager

Hello,

I've around questions and answers but I cannot find the one I need.

I'm selecting previous week in the time range when searching, and Splunk is starting the week on Sunday. How or What I need to change to make it start the week on Monday for all the users?

I want to change it in the search bar, without making people to add earliest/latest or similar in the search.

I'm sure is something easy, but I cannot find it.

Thank you in advance!

0 Karma
1 Solution

SOURAV_S
Explorer

Hi @mrovira,

Please check if this instruction works for you:

  1. Click on Settings
  2. Click on User Interface under 'Knowledge' sub-section.
  3. Click on Time Ranges
  4. Click on New Time Range on top right hand corner
  5. Since you want previous week Monday to be starting  point, configure your new time range as follows:
    1. Set earliest field as -5d@w1 (to denote previous Monday)
    2. Set latest field as @w6 (to denote Saturday, use @w5 for Friday)
  6. Make sure about your destination app.

These changes are available only for your user. To share it with everyone else, make sure you are admin and change the permissions. To configuring the time range to be available globally for all apps, and available for everyone to use and admins to modify: 

Settings > Time Ranges > your_custom_time_range_picker > Permissions

  1. Object should appear in All apps (system)
  2. Permissions: Read - Everyone, Write - admin

 

You're all done!

 

If this helps, mark this as solution.

Happy Splunking! 🙂

 
 

View solution in original post

SOURAV_S
Explorer

Hi @mrovira,

Please check if this instruction works for you:

  1. Click on Settings
  2. Click on User Interface under 'Knowledge' sub-section.
  3. Click on Time Ranges
  4. Click on New Time Range on top right hand corner
  5. Since you want previous week Monday to be starting  point, configure your new time range as follows:
    1. Set earliest field as -5d@w1 (to denote previous Monday)
    2. Set latest field as @w6 (to denote Saturday, use @w5 for Friday)
  6. Make sure about your destination app.

These changes are available only for your user. To share it with everyone else, make sure you are admin and change the permissions. To configuring the time range to be available globally for all apps, and available for everyone to use and admins to modify: 

Settings > Time Ranges > your_custom_time_range_picker > Permissions

  1. Object should appear in All apps (system)
  2. Permissions: Read - Everyone, Write - admin

 

You're all done!

 

If this helps, mark this as solution.

Happy Splunking! 🙂

 
 

richgalloway
SplunkTrust
SplunkTrust

Go to Settings->User interface->Time ranges and add a new time range defined as "-w@w1".

---
If this reply helps you, Karma would be appreciated.

mrovira
Engager

Hello,

 

You both were right, but I just can mark one as the solution 😞  Even though I used what you both said.

Thank you for your reply and time, it helped me! 😊

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...