Splunk Search

show last week values Mon-Sun and NOT Sun-Sat using earliest and latest

HattrickNZ
Motivator

How do I use earliest and latest to show last week Mon - Sun inclusive.

I have tried this earliest=-1w@w latest = @w but this is giving me Sun to Sat inclusive.

I would like to do it using this type of method earliest=-1w@w latest = @w

Tags (3)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi HattrickNZ,

you can use something like this instead:

w0 = Sunday w1 = Monday etc...

example: earliest=@w0 
 Searches from the current time to the previous Sun

Hope that helps ...

cheers, MuS

HattrickNZ
Motivator

tks jsut confirming that

earliest=-1w@w1 latest = @w1 will give me last week values for Mon - Sun

hmm, I can't seem to upload a picture file.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...