Splunk Search

Time range search

keshab
Path Finder

I have splunk indexed log for 6 months but I want to search log for 20 days only(from current date till 20 days ago) and draw a chart. What might be the possible search query??

Tags (2)
0 Karma

Ayn
Legend

Use the time picker in the search app. It gives you the ability to choose a time period to search.

Edit: to accomplish the same thing directly in the search string, there's lots of info on how to do this here: http://docs.splunk.com/Documentation/Splunk/4.2.2/User/ChangeTheTimeRangeOfYourSearch

Long story short, use earliest=-20d.

Ayn
Legend

OK. It wasn't clear from the original question. I updated my answer with more info.

0 Karma

keshab
Path Finder

I want the query for time range on search. Using the picker just gives you output I can't see what query it used.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...