Splunk Search

Setting Custom/Default Time in Splunk Search/Dashboard

eraasch
New Member

As the title suggests I am attempting to set a custom and default for a splunk dashboard that I created. When it opens I need it to snap to the previous weekday between 16:26 and 16:42 CST. Does anyone know how I would go about doing this?

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Use default earliest=-w@w+1d and default latest=@w5+1d

(Use advanced section if you are selecting from timerange picker UI.)

VatsalJagani_0-1640507460750.png

Then use this filter in the SPL search query

where date_hour=16 AND date_minute>=26 AND date_minute<=42
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...