Splunk Search

Splunk Query of Date and Time condition

splunk_venkat
New Member

Hi,

I am working on a splunk query to pull the records from daily basis depends on timinging.

For example 30m and 60m, for those I have confirmed the _time and relative time conditions to pull the transactions between this timeframe.

Now we have a requirement to pull the records as below,
30 mins <60 mins on Sat&Sun> for rest of the day

How could I achieve this requirment from splunk. Please suggest.

Thanks
Venkatesh.

0 Karma
Get Updates on the Splunk Community!

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...

Hunt Smarter, Not Harder: Discover New SPL “Recipes” in Our Threat Hunting Webinar

Are you ready to take your threat hunting skills to the next level? As Splunk community members, you know the ...