Splunk Search

How to get the earliest and latest for the last full hour

damucka
Builder

Hello,

How would I set the earliest and latest to the last full hour?
Example:
current time 5:19 pm
I want earliest=4pm and latest=5pm

Kind regards,
Kamil

1 Solution

woodcock
Esteemed Legend

In the SPL you can use earliest=-1h@h latest=@h and you can use the Advanced area of the Time picker you can use the same values.

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI damucka
try earliest=-h@h latest=@h, anyway you can also use the time picker to find the correct time intervals.

Ciao.
Giuseppe

0 Karma

woodcock
Esteemed Legend

In the SPL you can use earliest=-1h@h latest=@h and you can use the Advanced area of the Time picker you can use the same values.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...