Splunk Search

Splunk search earliest and latest in Splunk search

jaibalaraman
Path Finder

Splunk search 

" EventCode="4688" AND earliest="5/8/2024:10:07:20" latest="5/8/2024:10:17:20 " 

Could you please the time search is correct 

Tags (1)
0 Karma

thahir
Contributor

@jaibalaraman , your searches return a consistent set of results regardless of the time zone you are in.

0 Karma

thahir
Contributor

@jaibalaraman search can be in any time zone. can you elaborate your question what you need exactly

0 Karma

jaibalaraman
Path Finder

Hi 

I am trying to use earliest and latest on Date time 

Could you please advise the right format to use , i am not sure the below spl format is correct

Event Code="1234" AND earliest="5/8/2024:10:07:20" latest="5/8/2024:10:17:20

0 Karma

thahir
Contributor

hi @jaibalaraman , 

 

You can specify an exact time such as earliest="10/5/2021:20:00:00", or a relative time such as earliest=-h or latest=@w6.

When specifying relative time, you can use the now modifier to refer to the current time.

Tags (1)
0 Karma

apietsch
Splunk Employee
Splunk Employee

According to the documentation for search time modifiers you should be correct. Although example 4 and 5 on that page uses a different time format. Try the format from the examples.

---------------------
Chaos Smoother | Data Wrangler
0 Karma

jaibalaraman
Path Finder

Also the search can be done in  UTC or any time zone'

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...