Splunk Search

"In the last 30 Days" VS "Last 30 Days"

jkcouch
Explorer

When I have an inline search on a dashboard where the time range is set to -30d or -30d@d, my last time on my timechart is never consistently yesterday. Sometimes it is yesterday, other times its 5 days ago, depending on the search. How do I fix it so that it shows the null values on every timechart search?

I notice when I do a View Results, the time selection says "in the last 30 days", and when I change it to say "Last 30 days" Because "in the last 30 days" is not available, It works as it should.

Tags (3)
0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

Hard to tell without your data or a screenshot.

  • do you have any timechart options, what is the span ?
  • is it a dashboard, is there any other parameters in the XML that apply ?

If you remark is that the last event of the chart is not always right now, then it may be that you have a condition on the latest condition, or that there is no recent events.

please try to use inline : ealierst=-30d@d latest=now and compare

if you want to see what the timerange list is really, go to : Manager » User interface » Time ranges .

FYI : last_30_days "Last 30 days" earliest=-30d@d latest=now

View solution in original post

yannK
Splunk Employee
Splunk Employee

Hard to tell without your data or a screenshot.

  • do you have any timechart options, what is the span ?
  • is it a dashboard, is there any other parameters in the XML that apply ?

If you remark is that the last event of the chart is not always right now, then it may be that you have a condition on the latest condition, or that there is no recent events.

please try to use inline : ealierst=-30d@d latest=now and compare

if you want to see what the timerange list is really, go to : Manager » User interface » Time ranges .

FYI : last_30_days "Last 30 days" earliest=-30d@d latest=now

yannK
Splunk Employee
Splunk Employee

You can, and hard coded time ranges in the search, will have priority over the external time ranges.

0 Karma

jkcouch
Explorer

That answered my question perfectly. I didnt realize that you were able to set earliest and latest in the search line.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...