Hello - I was reading this: https://docs.splunk.com/Documentation/SCS/current/Search/TimemodifiersBut it is not very clear to me how to use the time modifiers properly.
index=blah sourcetype=blahfields _time index sourcetype GB| timechart span=1d sum(GB) as GigabytesHow would I draw my time chart to the end of the previous day over a 7-day period using a time modifier?Would it be: index=blah sourcetype=blah _index_earliest=-7d@d index_latest=-1d@dPlease advise, thank you.
@d takes you to the beginning of the day so for end of previous day you need latest=@d i.e. beginning of current day.
View solution in original post
Ahh... I tried -@d - didn't occur to me to try @d. Thank you.