Splunk Search

Time range not substituted by search

coreyCLI
Communicator

We have a SHC at version 8.1.3.  When we try to use "earliest" and "latest" in search we get results based on the earliest and latest however, its search events based on the time picker.  IE - If I create a search "index=main earliest=-15m latest=now" and the time picker is set to "24hours", the search will search all the events from the past 24 hours yet only display the results for the last 15 minutes.  If I test this same search outside of our SHC, on a standalone instance and use the "-15m" in search I get back the last minutes of events however I am ONLY search the last 15 minutes of events.  The search does not care about what is selected in the time picker.  As well, in the job inspector I see the "Your time range was substituted based on your search string" message as I would expect.  In the SHC cluster, I do not see this message.  

To add to the weirdness.  If I include a sourcetype in my search "index=main  sourcetype=stuff earliest=-15m latest=now" It works as expected and I see the message about substituting the timerage in the job inspector.  However, If I include more then one sourcetype, then it does NOT substitute the timerange.

0 Karma
1 Solution

coreyCLI
Communicator

For anyone interested.  I found an alias someone create using _time.  "FIELDALIAS-ts = ts as _time".  Once removed, all was working as it should.

View solution in original post

coreyCLI
Communicator

For anyone interested.  I found an alias someone create using _time.  "FIELDALIAS-ts = ts as _time".  Once removed, all was working as it should.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...