Splunk Search

What are these time modifiers doing?

splunkfuinator
New Member

I have a search where I want the first search to search the previous week (Sunday to Sunday) and then use the same search to search two weeks ago to the previous week. So, for example, if I ran the search on 11 December 2015, I want the first search to run from 29 November to 6 December, and one search to run 22 November to 29 November. I end up having the first week subtracted from the second week, which is why I have them set up as search / subsearch.

I read the time modifiers documentation (http://docs.splunk.com/Documentation/Splunk/6.2.0/SearchReference/SearchTimeModifiers), but I don't understand the logic behind the modifiers. Can someone please confirm if these are the right modifiers (below) to accomplish this. Additionally, when I run this as a scheduled report, does the time in the search override the time in saved in the Splunk query time selector?

Thanks in advance!

sourcetype="Login" earliest=-1w@w0 latest=@w
...
| appendcols [search sourcetype="Login" earliest=-2w@w1 latest=@w1

0 Karma
1 Solution

woodcock
Esteemed Legend

woodcock
Esteemed Legend

You need the TimeWrap app:

https://splunkbase.splunk.com/app/1645/

splunkfuinator
New Member

That looks awesome, but unfortunately I don't have admin privileges to install anything in Splunk. 😞

0 Karma

woodcock
Esteemed Legend

You can download it and clone the guts; that is what I would do.

0 Karma

splunkfuinator
New Member

Good point. Ty!

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...