Splunk Search

Time range not substituted by search

coreyCLI
Communicator

We have a SHC at version 8.1.3.  When we try to use "earliest" and "latest" in search we get results based on the earliest and latest however, its search events based on the time picker.  IE - If I create a search "index=main earliest=-15m latest=now" and the time picker is set to "24hours", the search will search all the events from the past 24 hours yet only display the results for the last 15 minutes.  If I test this same search outside of our SHC, on a standalone instance and use the "-15m" in search I get back the last minutes of events however I am ONLY search the last 15 minutes of events.  The search does not care about what is selected in the time picker.  As well, in the job inspector I see the "Your time range was substituted based on your search string" message as I would expect.  In the SHC cluster, I do not see this message.  

To add to the weirdness.  If I include a sourcetype in my search "index=main  sourcetype=stuff earliest=-15m latest=now" It works as expected and I see the message about substituting the timerage in the job inspector.  However, If I include more then one sourcetype, then it does NOT substitute the timerange.

0 Karma
1 Solution

coreyCLI
Communicator

For anyone interested.  I found an alias someone create using _time.  "FIELDALIAS-ts = ts as _time".  Once removed, all was working as it should.

View solution in original post

coreyCLI
Communicator

For anyone interested.  I found an alias someone create using _time.  "FIELDALIAS-ts = ts as _time".  Once removed, all was working as it should.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...