Splunk Search

Search for events after a certain time

jboustead
Explorer

Is it possible to run a search that will only include all the events for that day after a certain time? (using the time range picker to select the date only, so the time will be selected using the search query)

For example I am wanting the search to pick events after 8am for the day selected by the time range picker, 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If your events have the date_hour field (and it's reliable) then you can use it to filter events.

... | where date_hour >= 20 | ...

If you don't have that field then you can make your own.

... | eval date_hour = strftime(_time, "%H")
| where date_hour >= 20
---
If this reply helps you, Karma would be appreciated.

inventsekar
SplunkTrust
SplunkTrust

Hi @jboustead ,
"using the time range picker to select the date only, so the time will be selected using the search query"

if your events got hour value as a separate field, then, with "where" command, it may be possible. 

BUT that's a long and difficult route. 

The earliest and latest offers all possible combinations of time/date we can ever imagine. 

 

This example searches an index for the last 24 hours but omits any events returned from Midnight to 1:00 A.M., when downtime returns false log entries.

index=myindex ((earliest=-24h latest<@d) OR (earliest>=@d+1h))

This search specifies two time ranges:

  • 24 hours before the search is run, up to midnight
  • The beginning of the day that the search is run, starting at 1 hour after midnight or 1:00 A.M.

https://docs.splunk.com/Documentation/SplunkCloud/8.1.2009/Search/Specifytimemodifiersinyoursearch

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...