Splunk Search

show last week values Mon-Sun and NOT Sun-Sat using earliest and latest

HattrickNZ
Motivator

How do I use earliest and latest to show last week Mon - Sun inclusive.

I have tried this earliest=-1w@w latest = @w but this is giving me Sun to Sat inclusive.

I would like to do it using this type of method earliest=-1w@w latest = @w

Tags (3)
0 Karma

MuS
Legend

Hi HattrickNZ,

you can use something like this instead:

w0 = Sunday w1 = Monday etc...

example: earliest=@w0 
 Searches from the current time to the previous Sun

Hope that helps ...

cheers, MuS

HattrickNZ
Motivator

tks jsut confirming that

earliest=-1w@w1 latest = @w1 will give me last week values for Mon - Sun

hmm, I can't seem to upload a picture file.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...