Splunk newby here. I have a search that works if I change it every day but would like to add it to a dashboard for monitoring without having to change the date. It looks for all the newly created accounts in the current/past day, depending on what date I put in. The search is index=Activedirectory whenCreated="*,9/15/23" |table whenCreated, name, manager, title, description then search for last 24 hours. The format of the time is %H:%M:%S AM/PM, %a %m/%d/%Y. The 2 issues I am having are, how do you specify the AM/PM and how do you set up the search so that it will search for the last 24 hours using the current date. I was thinking it is "time()" but I am not successful in getting the results I need.
... View more