Hi Splunkers! I wish to get data in a specific time range using earliest and latest command . I have checked with time picker events are there within the specified range. But when I am trying to run a spl query its not working : I have tried with ISO format and custom format as shown below . When I use ISO format its giving error index=main sourcetype="access_combined_wcookie" earliest="2024-01-15T20:00:00" latest="2024-02-22T20:00:00" And when I use custom format as shown below its returning 0 events: index=main sourcetype="access_combined_wcookie" earliest="1/15/2024:20:00:00" latest="2/22/2024:20:00:00" Please help I want to do this using earliest and latest command only
... View more