Splunk Search

when Im using an earliest time value of -1mon, what does it do in cases like March 31st?

sideview
SplunkTrust
SplunkTrust

on March 13th, -1mon maps to February 13th, at whatever the current time of day is. And -1mon@d maps to February 13th 12AM.

In the dashboard we're dealing with, this is basically what we want.

However it seems like on March 29th, 30th and 31st, ie in cases where that date didnt exist in the previous month it seems splunkd must do something a little arbitrary.

So just to confirm, on all 3 of these days (3/29, 3/30, 3/31) does -1mon just map each to March 1st 12AM?

Tags (2)
1 Solution

jrodman
Splunk Employee
Splunk Employee

According to: http://docs.splunk.com/Documentation/Splunk/5.0/Search/Specifytimemodifiersinyoursearch#Specify_rela...

Important: When snapping to the nearest or latest time, Splunk always snaps backwards or rounds down to the latest time not after the specified time. For example, if it is 11:59:00 and you "snap to" hours, you will snap to 11:00 not 12:00.

If this applies, then you would expect it to snap March 29, 30, and 31 to February 28, 11:59:59 PM. In the leap year case, March 29 would map to February 29, at the same time of day.

View solution in original post

jrodman
Splunk Employee
Splunk Employee

According to: http://docs.splunk.com/Documentation/Splunk/5.0/Search/Specifytimemodifiersinyoursearch#Specify_rela...

Important: When snapping to the nearest or latest time, Splunk always snaps backwards or rounds down to the latest time not after the specified time. For example, if it is 11:59:00 and you "snap to" hours, you will snap to 11:00 not 12:00.

If this applies, then you would expect it to snap March 29, 30, and 31 to February 28, 11:59:59 PM. In the leap year case, March 29 would map to February 29, at the same time of day.

Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...