Hi,
i have records like this:
2013-03-05 01:02:03.456Z foo=bar value=key start="2013-03-05 05:00:00.000Z" end="2013-03-05 07:00:00.000Z"
Can i do search like "start >=-1d@d+3h" ?
Regards,
Jens
Take a look at relative_time(time, modifiers): http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/CommonEvalFunctions
Take a look at relative_time(time, modifiers): http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/CommonEvalFunctions
Thanks! That does it 🙂