Splunk Search

What does this mean ??auto_summarize.dispatch.earliest_time = -1d@h

macadminrohit
Contributor

I have a saved search which has this :

auto_summarize.dispatch.earliest_time = -1d@h

Not sure what time it indicates.

Tags (1)
0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

Hi @macadminrohit,

This is an auto summarization options.

auto_summarize.dispatch.<arg-name> = <string>
* Any dispatch.* options that need to be overridden when running the summary
  search.

In your case earliest_time will overridden with -1d@h.

Can you please refer this doc?
http://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Savedsearchesconf

Thanks

View solution in original post

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Hi @macadminrohit,

This is an auto summarization options.

auto_summarize.dispatch.<arg-name> = <string>
* Any dispatch.* options that need to be overridden when running the summary
  search.

In your case earliest_time will overridden with -1d@h.

Can you please refer this doc?
http://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Savedsearchesconf

Thanks

0 Karma

macadminrohit
Contributor

Thanks Kamlesh, basically i want to know what time does -1d@h denotes?

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

oooh.

Please check "List of time modifiers" and "How to specify relative time modifiers" in below link.
https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/SearchTimeModifiers

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...