Splunk Search

Search improvement

ibmbaranski
Engager

Hi - looking for a more efficient way to do this, if anyone has any tips:

 

index=xyz sourcetype=abc NOT user_email=unauthenticated (user_email=*) | eval day=strftime(_time, "%Y%m%d") | search day=20210723 | ...

 

Basically, can I filter on _time for a specific day without doing the eval then filter, this seems like an inefficient way to query if I can somehow say dayOf(_time)='20201010' or something like that...

Labels (1)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@ibmbaranski 

You can filter events using earliest and latest filter. Can you please try this?

index=xyz sourcetype=abc NOT user_email=unauthenticated (user_email=*) [| makeresults | eval earliest=strptime("20210723", "%Y%m%d"),latest=relative_time(earliest, "+1d@d") | table earliest latest | format] | ...

 

KV 

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...