Hello
If now, it is 30/12/2021 22:30, how can I search for timestamps from 29/12/2021 00:00:00 (i.e. beginning of 29/12/2021 or dynamically 'beginning of yesterday')?
I need this in a search code rather than the GUI presets etc.
Thanks!
@SplnkUse Please add the below earliest and lastest in your query after your index and sourcetype, example:
index=<<your_indexname>> sourcetype=<<your_sourcetypename>> earliest=-1d@d latest=now
Also if this reply helped you in solving your problem an up-vote would be appreciated.
Try earliest=-1d@d
See https://docs.splunk.com/Documentation/Splunk/8.2.4/SearchReference/SearchTimeModifiers for details.