Splunk Search

Why is the timerange in my CLI search not working properly in Splunk 5.0.6?

mgardler
New Member

There are lots of questions in here, but none work correctly:

Search:
splunk search "@aol" earliest=02/01/2011:00:00:00 latest=03/01/2011:00:00:00 -maxout=0

No matter what dates I put in here, the same results return
Also tried: ealiest_time, latest_time: index_earliest, index_latest

Everything returns the same information.....

What is a valid search string for a time range? (Running Splunk 5.0.6 (build 185560))

0 Karma

MuS
Legend

Hi mgardler,

using your search string like this

splunk search "@aol earliest=02/01/2011:00:00:00 latest=03/01/2011:00:00:00 -maxout=0"

works without problem. The result looks like this:

splunk search "@aol earliest=02/01/2011:00:00:00 latest=03/01/2011:00:00:00 -maxout=0"
INFO: Your timerange was substituted based on your search string

as prove take this run everywhere command

splunk search "index=_internal * earliest=10/29/2014:00:00:00 latest=10/31/2014:00:00:00  | stats count "
INFO: Your timerange was substituted based on your search string
count
-----
84357

hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...