Splunk Search

What are these time modifiers doing?

splunkfuinator
New Member

I have a search where I want the first search to search the previous week (Sunday to Sunday) and then use the same search to search two weeks ago to the previous week. So, for example, if I ran the search on 11 December 2015, I want the first search to run from 29 November to 6 December, and one search to run 22 November to 29 November. I end up having the first week subtracted from the second week, which is why I have them set up as search / subsearch.

I read the time modifiers documentation (http://docs.splunk.com/Documentation/Splunk/6.2.0/SearchReference/SearchTimeModifiers), but I don't understand the logic behind the modifiers. Can someone please confirm if these are the right modifiers (below) to accomplish this. Additionally, when I run this as a scheduled report, does the time in the search override the time in saved in the Splunk query time selector?

Thanks in advance!

sourcetype="Login" earliest=-1w@w0 latest=@w
...
| appendcols [search sourcetype="Login" earliest=-2w@w1 latest=@w1

0 Karma
1 Solution

woodcock
Esteemed Legend

woodcock
Esteemed Legend

You need the TimeWrap app:

https://splunkbase.splunk.com/app/1645/

splunkfuinator
New Member

That looks awesome, but unfortunately I don't have admin privileges to install anything in Splunk. 😞

0 Karma

woodcock
Esteemed Legend

You can download it and clone the guts; that is what I would do.

0 Karma

splunkfuinator
New Member

Good point. Ty!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...