Hi
How can I exclude this time range from search 23:55 to 06:00
I'm using below spl but minutes required.
index="my-index" NOT (date_hour>=23 date_hour<6)
any idea?
Thanks,
and for completeness, rather than using a NOT clause
https://docs.splunk.com/Documentation/Splunk/8.2.2/Search/Quicktipsforoptimization
use
index="my-index" (date_hour>=6 AND (date_hour<23 OR (date_hour=23 date_minute<55)))
not done any detailed comparisons of timings...
and for completeness, rather than using a NOT clause
https://docs.splunk.com/Documentation/Splunk/8.2.2/Search/Quicktipsforoptimization
use
index="my-index" (date_hour>=6 AND (date_hour<23 OR (date_hour=23 date_minute<55)))
not done any detailed comparisons of timings...
Does this help?
index="my-index" NOT ((date_hour>=23 date_minute>=55) date_hour<6)
Shouldn't work 😉 You can't have a time which has both hour>23 and hour<6. You wrapped the day around midnight 😉
The condition should be
NOT (date_hour>23 date_minute>55) NOT date_hour<6
alternatively
NOT ((date_hour>23 date_minute>55) OR date_hour<6)