Getting Data In

What is the correct earliest_time format for searches when programmatically querying Splunk?

the_wolverine
Champion

I'm using Python SDK (or some other client) to query Splunk and its not accepting my date format. What is the correct format to specify for earliest_time?

1 Solution

the_wolverine
Champion

earliest_time = YYYY-MM-DDTHH:MM:SS

Example: earliest_time = 2017-03-14T10:0:0

View solution in original post

cmerriman
Super Champion

here is a doc about it:

http://dev.splunk.com/view/SP-CAAAEE5#oneshotjo

"earliest_time": "2017-03-14T12:00:00.000-07:00"
0 Karma

the_wolverine
Champion

earliest_time = YYYY-MM-DDTHH:MM:SS

Example: earliest_time = 2017-03-14T10:0:0

Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...