Splunk Search

Show last day's data from 6pm to next day 6pm

Hi,
I want to display the data only from last day's 6pm to next day 6pm.
I tried various forms of earliest and latest. But couldn't figure it out how.
Please Help...!!

0 Karma
1 Solution

Motivator

Hello

You can use this on you search string:

earliest=@d-6h latest=@d+18h

Regards

View solution in original post

Motivator

Hello

You can use this on you search string:

earliest=@d-6h latest=@d+18h

Regards

View solution in original post

Thanks gfuente...

0 Karma