Splunk Search

which overrides first either time modifier or time range picker?

jmohan1984
New Member

I have created Splunk query with time modifiers "earliest" and "latest" ( for eg. earliest="15/01/2022 8 am" latest="15/01/2022 10 pm" ) and also I have selected time range in the time ranger picker (for eg. 23/12/2022 8 am to 23/12/2022 10 pm)

Splunk Query:

 

timeformat="%m-%d-%Y %l:%M %p" earliest="15-01-2022 08:00 AM" latest="15-01-2022 10:00 PM" index="mobileApp"  homepage

 

 

Time range picker values in UI:

From: 23/12/2022 8 am; To: 23/12/2022 10 pm

 

whenever, I click 'search' button, time range picker overrides the time modifiers earliest/latest values which are used in the Splunk query

Question:
could you please help me on overriding 'time range picker' values ( I need results between 15/01/2022 8 am to 15/01/2022 10 pm based on 'time modifiers' only)

Your answer would be greatly appreciated!

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The times used for earliest and latest in your query should override the timepicker values. The job inspector should have a message saying this has happened

ITWhisperer_0-1660294329582.png

 

0 Karma
Get Updates on the Splunk Community!

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Admin Console: A Single, Unified Interface for All Your Cloud Admin Needs

WATCH NOWJoin us to learn how the admin console can save you time and give you more control over the Splunk® ...