Splunk Search

What time modifiers do I use for earliest and latest for day before yesterday, 2 days before yesterday, 3 days before yesterday, and so on?

pavanae
Builder

For yesterday's results we give the earliest and latest as below

earliest=-1d@d latest=@d

Simillarly, what could be the earliest and latest for day before yesterday, 2 days before yesterday, 3 days before yesterday and so on?

0 Karma
1 Solution

sundareshr
Legend

Just build on that..

earliest=-1d@d latest=@d
earliest=-2d@d latest=-1d@d
earliest=-3d@d latest=-2d@d
...

View solution in original post

sundareshr
Legend

Just build on that..

earliest=-1d@d latest=@d
earliest=-2d@d latest=-1d@d
earliest=-3d@d latest=-2d@d
...

chow11
New Member

How can i do similarly for certain time range?
I want to run my query for every 5minutes and 15 minutes (i have 2 diff queries).
how can i get results for past 5 minutes and how can i get results for past 15 minutes using "earliest= latest=" parameters.

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @chow11, since this is an older post you might want to create a new question. Here's some info on how to ask a question http://docs.splunk.com/Documentation/Splunkbase/splunkbase/Answers/Questions

0 Karma
Get Updates on the Splunk Community!

This Week's Community Digest - Splunk Community Happenings [9.26.22]

Get the latest news and updates from the Splunk Community here! Upcoming User Group Events! 👏 Check ...

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...