Splunk Search

Where _time > 3/22/2018

griffinpair
Path Finder

I have events that only time stamp is the Splunk generated _time and I only need to return events after a certain date, 3/22/2018. Simply adding "Where _time > 3/22/2018" does not work and I have attempted converting _time and comparing against that to no avail.

Any suggestions?

jihape
Path Finder

If _time is the time you want to use for searches, using the time picker should work just fine.

skoelpin
SplunkTrust
SplunkTrust

Try this

index=...
| eval epoch=strptime("YOUR_TIME_FIELD", "%m/%d/%Y") 
| where epoch >1521748648
Get Updates on the Splunk Community!

Get Schooled with Splunk Education: Explore Our Latest Courses

At Splunk Education, we’re dedicated to providing incredible learning experiences that cater to every skill ...

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...