Splunk Search

How to get the earliest and latest for the last full hour

damucka
Builder

Hello,

How would I set the earliest and latest to the last full hour?
Example:
current time 5:19 pm
I want earliest=4pm and latest=5pm

Kind regards,
Kamil

1 Solution

woodcock
Esteemed Legend

In the SPL you can use earliest=-1h@h latest=@h and you can use the Advanced area of the Time picker you can use the same values.

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI damucka
try earliest=-h@h latest=@h, anyway you can also use the time picker to find the correct time intervals.

Ciao.
Giuseppe

0 Karma

woodcock
Esteemed Legend

In the SPL you can use earliest=-1h@h latest=@h and you can use the Advanced area of the Time picker you can use the same values.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...