Trying to use the date option within splunk, it ignores what I choose and adds data from other days.,When I specify a date range it seems to ignore this and provide information for all items vs the date I select.
I found the answer -
https://docs.splunk.com/Documentation/Splunk/8.0.3/SearchReference/Timechart
timechart span=21d
I found the answer -
https://docs.splunk.com/Documentation/Splunk/8.0.3/SearchReference/Timechart
timechart span=21d
You can do this by writing your spl -> then in Timerange picker, select Date & Time range
-> In the dropdown, select Between
and the set the exact date, for which you want to see the logs, and in hours, start with 00:00:00.000
-> Set the same date again the second filter and set the time to 23:59:59.000
This should make sure that you only see the logs from that particular date only.