- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello -
I was reading this: https://docs.splunk.com/Documentation/SCS/current/Search/Timemodifiers
But it is not very clear to me how to use the time modifiers properly.
index=blah sourcetype=blah
fields _time index sourcetype GB
| timechart span=1d sum(GB) as Gigabytes
How would I draw my time chart to the end of the previous day over a 7-day period using a time modifier?
Would it be:
index=blah sourcetype=blah _index_earliest=-7d@d index_latest=-1d@d
Please advise, thank you.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
@d takes you to the beginning of the day so for end of previous day you need latest=@d i.e. beginning of current day.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
@d takes you to the beginning of the day so for end of previous day you need latest=@d i.e. beginning of current day.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ahh... I tried -@d - didn't occur to me to try @d. Thank you.
data:image/s3,"s3://crabby-images/fde3a/fde3a0b9d86efccda0ff50bfe5dc3fbacbe25b77" alt=""