Splunk Search

"In the last 30 Days" VS "Last 30 Days"

jkcouch
Explorer

When I have an inline search on a dashboard where the time range is set to -30d or -30d@d, my last time on my timechart is never consistently yesterday. Sometimes it is yesterday, other times its 5 days ago, depending on the search. How do I fix it so that it shows the null values on every timechart search?

I notice when I do a View Results, the time selection says "in the last 30 days", and when I change it to say "Last 30 days" Because "in the last 30 days" is not available, It works as it should.

Tags (3)
0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

Hard to tell without your data or a screenshot.

  • do you have any timechart options, what is the span ?
  • is it a dashboard, is there any other parameters in the XML that apply ?

If you remark is that the last event of the chart is not always right now, then it may be that you have a condition on the latest condition, or that there is no recent events.

please try to use inline : ealierst=-30d@d latest=now and compare

if you want to see what the timerange list is really, go to : Manager » User interface » Time ranges .

FYI : last_30_days "Last 30 days" earliest=-30d@d latest=now

View solution in original post

yannK
Splunk Employee
Splunk Employee

Hard to tell without your data or a screenshot.

  • do you have any timechart options, what is the span ?
  • is it a dashboard, is there any other parameters in the XML that apply ?

If you remark is that the last event of the chart is not always right now, then it may be that you have a condition on the latest condition, or that there is no recent events.

please try to use inline : ealierst=-30d@d latest=now and compare

if you want to see what the timerange list is really, go to : Manager » User interface » Time ranges .

FYI : last_30_days "Last 30 days" earliest=-30d@d latest=now

yannK
Splunk Employee
Splunk Employee

You can, and hard coded time ranges in the search, will have priority over the external time ranges.

0 Karma

jkcouch
Explorer

That answered my question perfectly. I didnt realize that you were able to set earliest and latest in the search line.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...