You can set earliest/latest using a subsearch if necessary. In this case, you can set earliest using an eval based on info_max_time , created via addinfo .
Try this, which should set earliest to be essentially latest-1d :
host=host123 index=security123 sourcetype="SplunkLog123" [| makeresults | addinfo | eval earliest=relative_time(info_max_time, "-1d") | table earliest]
Edit:
Try this instead:
[| makeresults | addinfo | eval earliest=relative_time(info_max_time, "-1d") | table earliest] host=host123 index=security123 sourcetype="SplunkLog123"
I've seen issues before with Splunk interpreting earliest=/latest= as key/values pairs of the data itself (instead of time modifiers) if they aren't at the start of the query.
... View more