Splunk Search

show last week values Mon-Sun and NOT Sun-Sat using earliest and latest

HattrickNZ
Motivator

How do I use earliest and latest to show last week Mon - Sun inclusive.

I have tried this earliest=-1w@w latest = @w but this is giving me Sun to Sat inclusive.

I would like to do it using this type of method earliest=-1w@w latest = @w

Tags (3)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi HattrickNZ,

you can use something like this instead:

w0 = Sunday w1 = Monday etc...

example: earliest=@w0 
 Searches from the current time to the previous Sun

Hope that helps ...

cheers, MuS

HattrickNZ
Motivator

tks jsut confirming that

earliest=-1w@w1 latest = @w1 will give me last week values for Mon - Sun

hmm, I can't seem to upload a picture file.

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...