Hello Everyone. I am pretty new with splunk. I'll try to be brief: I know that a specific event happened at an exact time. So I want to know what happened on that machine at that time and in the last 5 minutes. This is to see what the machine was doing 5 minutes prior triggering the alert. I got this query: (where xxxxxxxxx is the index, sourcetype and name of the machine I want to look) *********************************************************************************************** xxxxxxxxx [| gentimes start=-1 | addinfo | eval earliest=relative_time(info_min_time,"-5m") |table earliest latest | format "" "" "" "" "" "" ] *********************************************************************************************** This works well if I manually select in the timepicker anything. For example I click on "last 15 minutes", the query is in reality done for the last 20 minutes (as I want as well the 5 minutes before the earliest time). The problem comes when I try to type an exact time in the query itself. I am trying by putting for example: earliest=10/19/2018:00:00:00 but it does not work. I am even trying earliest=-1d and it just does not listen to it, it listens to whatever is chosen in the timepicker. Maybe I am taking the wrong approach with my initial query. Has anybody been in this situation? Or anyone can shed some light here? Thank you very much in advance.
... View more