Splunk Search

between earliest=beginning of the previous day (00:00:00) latest=end of previous day (23:59:59)

jclemons7
Path Finder

I need a way to programatically calculate the beginning of the previous day and the end of he previous day.

Any help is greatly appreciated.

0 Karma

somesoni2
Revered Legend

How about using the relative time (hoping the programmatically in splunk search is asked here)

your base search earliest=-1d@d latest=@d

jclemons7
Path Finder

does that actually put it at 00:00:00 to 23:59:59 for instance?.. it's not relative to the time I run the query?

0 Karma

somesoni2
Revered Legend

It will put (if I run it today Feb 12 ) earliest=02/11/2016 00:00:00 to latest=02/12/2016 00:00:00.

It relative to the time you runt he query. You can check/test this option from the Splunk's search page itself. In time range picker dropdown, the last section is advanced, there you can test relative time values and can see actual resolved date just below the text boxes.

alt text

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...